Post ·
Migrating a Windows Server 2012 PKI to 2022
Moving an offline root CA and two intermediate CAs from Windows Server 2012 to 2022: what breaks, how to back up and restore each CA, and how to roll back.

Overview
Certification authorities are built to outlive the hardware they run on, so sooner or later you move one. This is how I moved a two-tier Windows PKI — an offline root CA and two online intermediate CAs — from Windows Server 2012 to new Windows Server 2022 servers, keeping each CA's name and key. The KMS host followed straight after.
What actually breaks a CA migration
The database backup and restore is the easy part. What bites is everything the existing certificates already point at.
- CRL and AIA publication points. Every certificate the old CA issued carries URLs where clients check revocation and fetch the issuer chain. If those stop resolving after the move, valid certificates start failing validation. Confirm the CDP and AIA locations resolve, and are published from the new servers, before you retire the old ones.
- Certificate templates live in Active Directory. They aren't in the CA backup. Record which templates each CA publishes so you can publish the same set on the new CA.
- The CA's host name. The CA keeps its name and key, but the server name changes. That's why the registry edit below matters: get CAServerName wrong and the restored CA won't start.
- The offline root's CRL. The root has to come online for its own move, and its CRL has an expiry date. Publish a fresh root CRL while it's up so the chain doesn't expire mid-project.
Plan
- Build three Windows Server 2022 servers: one that stays offline for the root, and one for each intermediate.
- Move the root first, then each intermediate, one at a time.
- Keep the 2012 servers intact until the new CAs are proven. The rollback depends on them.
Step 1 — Back up each 2012 CA
- Record the templates listed in the Certificate Templates folder of the Certification Authority snap-in.
- In the snap-in, right-click the CA name, then All Tasks → Back up CA.
- Select Private key and CA certificate and Certificate database and certificate database log.
- Choose an empty folder the new server can reach, and set a strong password for the private-key backup.
- Finish, and check the backup contains the private key, the CA certificate, the issued log and pending requests.
Step 2 — Export the CA configuration from the registry
On the same server, export the Certificate Services configuration key:
reg export HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration C:\CABackup\CertSvc-Config.regOpen the .reg file in a text editor and change CAServerName to the new server's fully qualified host name.
Step 3 — Move the role to the 2022 server
- Remove the Certificate Services role from the 2012 server.
- Install the role on the 2022 server. When you configure it, choose Use existing private key and select the CA certificate from the backup, so the new CA keeps its original name and key.
- Stop Certificate Services, import the edited .reg file (right-click, Merge), and restore the CA database and log from the backup (All Tasks → Restore CA).
- Start Certificate Services, publish a fresh CRL, and publish the same templates you recorded in Step 1.
- Check the result in the Enterprise PKI snap-in (pkiview.msc): every CDP and AIA location should show OK.
The service and CRL commands, for reference:
net stop certsvc
net start certsvc
certutil -crlRoll back
This works only while the 2012 servers and current backups still exist.
- Remove the role from the 2022 server.
- Reinstall the role on the 2012 server.
- Set CAServerName in the registry backup back to the old host name, and merge it.
- Restore the CA database and start Certificate Services.