# Windows 2012 PKI Upgrade to 2022

> Migrated an offline root CA and two intermediates from Windows Server 2012 to 2022, keeping every CA's name and key.

Canonical: https://mikereams.com/work/windows-2012-pki-upgrade-to-2022

Year: 2023  
Change: CA 2012 → CA 2022  
Technology: Certificate Authority, Active Directory  
Topics: PKI, Security, Cryptography, Certificate Authority, Private Key Infrastructure, IT Infrastructure  
Write-ups: [Migrating a Windows Server 2012 PKI to 2022](https://mikereams.com/writing/pki-infrastructure-upgrade)  
Diagrams: [TLS Certificate Architecture Standard](https://mikereams.com/diagrams/tls-certificate-architecture-standard)

![Windows 2012 PKI Upgrade to 2022](https://mikereams.com/work/684c6c95bc0d0e04856788d9d1f6eefef9e3ea0c-1000x380.jpg)

## The situation

The client's certificate authorities ran on Windows Server 2012, heading for end of support. Every system that trusts or validates their certificates depends on them, so the move could not break a chain.

## What I did

- Moved the offline root CA and both online intermediate CAs to new Windows Server 2022 servers, keeping each CA's name and key.
- Kept the revocation (CRL) and issuer (AIA) publication points resolving, so previously issued certificates kept validating.
- Re-published the certificate templates, which live in Active Directory rather than in the CA backup.
- Kept the 2012 servers and backups intact as the rollback path until the new CAs were proven.

The step-by-step: [Migrating a Windows Server 2012 PKI to 2022](https://mikereams.com/writing/pki-infrastructure-upgrade). The [KMS host](https://mikereams.com/work/key-management-services-upgrade) moved next.
