Address 5 of Active Directory server problems by migration-application of recovery server

Source: Internet
Author: User


4 Restore the original server application

After the original server (a computer) is detached from the domain, reinstall Windows Server R2, and then refer to section 3rd and 5th above, upgrade the a computer to an additional domain controller, demote the D computer, and then detach D from the domain, which has been introduced, not introduced, Only the main steps are described below.

(1) To install a new Windows Server R2 for a computer, after installation, modify the computer name to Dcser and restart the computer.

(2) Set the IP address to a temporary transit address, for example, 172.16.20.109,dns is 172.16.20.1, upgrade to an additional domain controller.

(3) Upgrade A to the primary domain controller, remove the IP address of 172.16.20.1 on D, and keep only the 172.16.20.110 IP address. Add the IP address of the 172.16.20.1 on a.

(4) Demote d from the Active Directory domain.

(5) Delete the temporary address on a, leaving only the IP address of the 172.16.20.1.

After the a server is restored to an Active Directory server, install the certificate and DHCP service, and then restore the relevant data with the original backup after installation. First, the recovery certificate service is described in the following main steps.

(1) Open "Server Manager", select "Add Roles and Features", as shown in 6-1.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/72/DB/wKioL1Xu1augMD1RAAERak1eBjM655.jpg "/>

Figure 6-1 Adding roles and features

(2) Select "Dcser.heinfo.local" in the "Select Destination Server" dialog box, 6-2 is shown.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/72/DE/wKiom1Xu04ChXHc7AAHeRPBhAHU562.jpg "/>

Figure 6-2 Selecting a target server

(3) in the Select Server Roles dialog box, select Active Directory Certificate Services and DHCP server, as shown in 6-3.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/72/DE/wKiom1Xu04CAOHKMAAISooV_RPQ107.jpg "/>

Figure 6-3 Selecting a server role

(4) In the Select Role Services dialog box, select Certification Authority and Certification authority Web enrollment, as shown in 6-4.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/72/DB/wKioL1Xu1avhKWXWAAGrEVSkA3o596.jpg "/>

Figure 6-4 Selecting a role service

(5) In the Confirm Installation Selections dialog box, click the Install button to begin installing Active Directory Certificate Services and DHCP server, as shown in 6-5.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/72/DE/wKiom1Xu04CwVmnrAAH8USw8sd8521.jpg "/>

Figure 6-5 Confirming the installation of the selection

(6) After the installation progress is complete, in the Installation Progress dialog box, click Configure Active Directory Certificate Services on the destination server, as shown in 6-6.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/72/DB/wKioL1Xu1azTy4nkAAII0hq2jKQ566.jpg "/>

Figure 6-6 Installation Progress

(7) If you close the Installation Progress dialog box early, in Server Manager, select the Configure Active Directory Certificate Services on target server link, as shown in 6-7.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/72/DB/wKioL1Xu1azwNHTBAAFfF3OZqmg502.jpg "/>

Figure 6-7 Configuring Certificate Services

(8) In the Credentials dialog box, select the Default domain administrator account, and click the Next button, as shown in 6-8.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/72/DE/wKiom1Xu04HRaj4SAAGDW_I5iEY402.jpg "/>

Figure 6-8 Specifying credentials

(9) In the Role Services dialog box, select the service you want to configure, and select certification Authority and Certification authority Web enrollment, as shown in 6-9.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/72/DB/wKioL1Xu1azzQfbbAAFVjBKgmvA400.jpg "/>

Figure 6-9 Role Services

(10) In the Setup Type dialog box, select Enterprise CA, as shown in 6-10. If your original server has a standalone CA installed, select stand-alone CA.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/72/DE/wKiom1Xu04LD7ttrAAGiH3NyNPE516.jpg "/>

Figure 6-10 Specifying the CA setup type

(11) In the CA Type dialog box, specify the CA type, where "root CA" is selected, as shown in 6-11.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/72/DB/wKioL1Xu1a3xjQ1xAAG4HCoEa_c614.jpg "/>

Figure 6-11 Specifying the CA type

(12) In the Private Key dialog box, specify the private key type, where you select Use an existing private key, and in parallel select Select a certificate and use its associated private key, as shown in 6-12.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/72/DE/wKiom1Xu04LSS9sBAAHyaZFgHCw651.jpg "/>

Figure 6-12 Specifying the private key type

(13) In the existing Certificate dialog box, click the Import button, as shown in 6-13.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/72/DB/wKioL1Xu1a2ieqluAAGetRDjGCM508.jpg "/>

Figure 6-13 Selecting an existing certificate for a CA

(14) In the Import existing Certificate dialog box, click the Browse button, browse to select the certificate in the path of the certificate server that you backed up in 1 backup DHCP and Certificate Server, and then enter the password that you set for the backup, as shown in 6-14.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/72/DE/wKiom1Xu04KRxUlvAADMNx0SXUg126.jpg "/>

Figure 6-14 Selecting a backed up CA root certificate

(15) Return to the existing Certificate dialog box, at which point the backed-up CA root certificate has been imported, as shown in 6-15.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/72/DB/wKioL1Xu1a2Ama-gAAHDhEshYJ4970.jpg "/>

Figure 6-15 Selecting an existing certificate

(16) In the CA Database dialog box, specify the database location, where the default value is selected, as shown in 6-16.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/72/DE/wKiom1Xu04OimGdUAAE8jtTl9Gk024.jpg "/>

Figure 6-16 Specifying CA data

(17) in the "Confirm" dialog box, display the currently installed Certificate Services and configuration method, check the error after clicking the "Configure" button, 6-17 is shown.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/72/DB/wKioL1Xu1a7Bfr_FAAGmCk_sMCA301.jpg "/>

Figure 6-17 Confirm

(18) In the Results dialog box, display the results of the configuration, as shown in 6-18.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/72/DE/wKiom1Xu04PBXUfpAAE0f8HEM2k693.jpg "/>

Figure 6-18 Configuration Results

(19) Go back to "Server Manager", navigate to "AD CS" on the left, right click on the server computer name in the right pane, and select "Certification Authority" in the popup dialog box, 6-19.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/72/DE/wKiom1Xu04PQRuI_AAFBJGYpaa4656.jpg "/>

Figure 6-19 Certification Authority

(20) Open certification Authority, right-click the computer name, and in the dialog box that pops up, select all Tasks → restore CA, as shown in 6-20.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/72/DB/wKioL1Xu1a6AagFMAAG4fUSKV1I505.jpg "/>

Figure 6-20 Restoring a CA

(21) Open the "Welcome to the Certification Authority Restore Wizard" dialog box, as shown in 6-21.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/72/DB/wKioL1Xu1a_B1HI1AAGxM2q-BOo471.jpg "/>

Figure 6-21 Restore Wizard

(Please take the next article)

This article from "Wang Chunhai blog" blog, declined reprint!

Address 5 of Active Directory server problems by migration-application of recovery server

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.