Migrate an intermediate CA to a new root

ad-certificate-servicescertificate-authoritycrl

Using the Microsoft CA is there any way to cut over to a new certificate authority from an intermediate authority?

Both my systems are Microsoft CAs – I have a 2008 R2 Enterprise CA (intermediate) and an old 2003 CA (root). The 2003 box bit the dust and I don't have good backups. I still have a few months before the CRL expires; instead of having to cut over to a new intermediate authority is there a ready way to simply point this intermediate authority to a new offline CA?

Best Answer

MS have good docs in this area, e.g.: Active Directory Certificate Services Migration Guide