|
|
Question : Migration of PKI infrastructure to a non-PKI infrastructure
|
|
Hello all- I have a client with multiple AD infrastructures (growth through acquisition) and we are putting together a comprehensive migration strategy to consolidate them into a single 2003 AD forest. Two of their 20 AD forests have implemented their own internal Public Key Infrastructure (PKI) to encrypt their email and to provide wireless authentication etc.. Upon migration of these 2 sites to the new forest, will PKI no longer be relevant? Will anything break? We'll be using 3rd party migration tools such as Quest to assist with AD account and Lotus Notes synchronization with Exchange 2007. Any and all help is greatly appreciated.
|
Answer : Migration of PKI infrastructure to a non-PKI infrastructure
|
|
As long as you don't intend on using the certificates on the other servers they will primarily be used for those two specific forests.
Now if you plant on migrating those PKI Certs for the whole network your going to have make some changes and make a bridged CA.
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03qswp.mspx
To answer your question no it wont break it.
|
|
|
|