Answered Demote DC while keeping as DHCP & CA

  • 2012年7月27日 16:56
     
     

    My question is: Will demoting the 2003 server while leaving it as a DHCP and CA cause problems? I can transfer all that to the other physical DC, but if I don't have to right now I can focus on the project that is requiring our domain level to be raised.

    Ok, so here is my scenario:

    3 Domain controllers, 1 virtual and 2 physical:

    DC1: 2008 R2, Virtual, has all FSMO roles, Global catalog, Certificate Authority, in production for 2 years

    DC2: 2003 SP1, Physical, DHCP, Certificate Authority, in production since the creation of time

    DC3: 2008 R2, Physical, in production 6 months

    For certain reasons we need to raise our domain level to 2008, so I ultimately need to demote the 2003 DC.

    I know a member server can be a CA and DHCP, I just want to make sure the demotion process won't break things, other than having to authorize it after demotion.



    • 編集済み COWBSH 2012年7月27日 20:12
    • 編集済み COWBSH 2012年7月27日 20:13
    •  

すべての返信

  • 2012年7月28日 3:58
     
     

    I don't think that you will have problem. The DHCP's role can be on anything and the CA'S role is binded to the machine name and domain membership. The removal of the DC's role should not affect's them.


    MCP | MCTS 70-236: Exchange Server 2007, Configuring

    Want to follow me ?  |  Blog: http://www.jabea.net | http://blogs.technet.com/b/wikininjas/

  • 2012年7月28日 8:15
     
     

    transferring the roles to another domain controller and removing the active directory will not effect the DHCP and CA. 


    http://www.arabitpro.com

  • 2012年7月28日 8:27
     
     回答済み
    to my experience you cannot demote a dc (windows 2003) while it has the ca role. you will have to backup the ca, and restore it after the demote (http://support.microsoft.com/kb/298138/en-us)
  • 2012年7月28日 18:30
     
     回答済み

    FZB give good point to you

    If you have CA on 2003 server DC you need to backup it, uninstall it. then you will have option to demote. afterwards you will install CA again and restore it.

    FOr DHCP my suggestion is to move it to another server if DHCP is on your 2003 server, before you demote it.


    Best regards
    Dubravko Marak
    MCP
    Blog: Windows Server Administration
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. Please VOTE as HELPFUL if the post helps you. This can be beneficial to other community members reading the thread.

  • 2012年7月28日 18:42
     
     

    Thank you for pointing this out, I had missed this point. If I do not need to move DHCP to a new server this will be fairly simple process. 

    As for the DHCP, I've heard both ways.  MS support advised I am alright leaving the DHCP intact while demoting, but I'll wait to see if more people weigh in with their experiences.

  • 2012年7月28日 19:06
     
     

    DHCP moving is very simple if you don't have multiple subnets. I've done this few times without any problem.


    Best regards
    Dubravko Marak
    MCP
    Blog: Windows Server Administration
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. Please VOTE as HELPFUL if the post helps you. This can be beneficial to other community members reading the thread.