How to Backup a Windows Certificate Server
How to Backup a Windows Certificate Server
A lots of different systems and platforms use certificates and Public Key Infrastructure (PKI). Many companies have decided to implement an internal Certification Authority to issue certificates to computers, users, and other Certification Authorities.
The loss of PKI data can be devastating, even requiring a full enterprise rebuild in some cases. So you need to ensure that you back up not just the CA system itself, but the CA’s database as well. This applies even when you’re using Active Directory integrated PKI as an Enterprise CA.
Although the steps seem simple, they’re very important. Without all of these steps you will be challenged to recover the CA after a catastrophic loss.
Steps to backing up a Certificate Server
The steps to back up a Windows Certificate Server running on Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, or Windows Server 2012 R2 are all the same. They are:
- Run Certutil –backupDB on the CA. This backs up the entire CA database to a folder of your choice.
- Run Certutil –backupKey on the CA. This backs up the certificate and private key that the CA is currently using to a PFX file in the folder of your choice.
- Perform a full system backup. Use any tool you like. The built-in Windows Backup is fine, and if your organization uses a higher-end backup solution, even better. Make certain that your backup includes the folders that you specified in the Certutil commands!
- Perform a backup of the Active Directory database. Do not rely on replication to save you if you need to recover from a major incident, as bad data is just as easily and quickly replicated as good data. Again, use whatever tool or process you prefer.
Now store the backed up data in a safe place and pray that you never need it!
If you want more Windows PKI articles please be sure to drop me a comment.
Take care!
Mike Danseglio -CISSP / CEH
Interface Technical Training – Technical Director and Instructor
You May Also Like
A Simple Introduction to Cisco CML2
0 3850 0Mark Jacob, Cisco Instructor, presents an introduction to Cisco Modeling Labs 2.0 or CML2.0, an upgrade to Cisco’s VIRL Personal Edition. Mark demonstrates Terminal Emulator access to console, as well as console access from within the CML2.0 product. Hello, I’m Mark Jacob, a Cisco Instructor and Network Instructor at Interface Technical Training. I’ve been using … Continue reading A Simple Introduction to Cisco CML2
Cable Testers and How to Use them in Network Environments
0 713 1This content is from our CompTIA Network + Video Certification Training Course. Start training today! In this video, CompTIA Network + instructor Rick Trader demonstrates how to use cable testers in network environments. Let’s look at some tools that we can use to test our different cables in our environment. Cable Testers Properly Wired Connectivity … Continue reading Cable Testers and How to Use them in Network Environments
Government Edition – Encrypting a USB Flash Drive in Windows 10
0 271 2In this video, Security Instructor Mike Danseglio demonstrates how to use BitLocker in Window 10 to secure files on a USB Flash drive that adhere to stricter data protection requirements as found inside Government entities. BitLocker 2-day instructor-led training is now available at Interface: BITLOCK: Planning and Deploying BitLocker Drive Encryption Training Video Transcription: Hi. … Continue reading Government Edition – Encrypting a USB Flash Drive in Windows 10