{"id":76884,"date":"2016-02-16T00:01:09","date_gmt":"2016-02-16T00:01:09","guid":{"rendered":"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/?p=76884"},"modified":"2019-02-18T09:19:51","modified_gmt":"2019-02-18T16:19:51","slug":"migrate-windows-ca-from-csp-to-ksp-and-from-sha-1-to-sha-256-part-2","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/scripting\/migrate-windows-ca-from-csp-to-ksp-and-from-sha-1-to-sha-256-part-2\/","title":{"rendered":"Migrate Windows CA from CSP to KSP and from SHA-1 to SHA-256: Part 2"},"content":{"rendered":"<p><strong>Summary<\/strong>: Thomas Rayner, Microsoft Cloud &amp; Datacenter Management MVP, shows how to back up your Windows certification authority as a part of migrating from CSP to KSP and from SHA-1 to SHA-256.<\/p>\n<p>Hello! I\u2019m Thomas Rayner, a proud Cloud &amp; Datacenter Management Microsoft MVP, filling in for The Scripting Guy this week. You can find me on Twitter (<a href=\"https:\/\/twitter.com\/MrThomasRayner\">@MrThomasRayner<\/a>) or on my blog, <a href=\"http:\/\/workingsysadmin.com\/\" target=\"_blank\">Working Sysadmin: Figuring stuff out at work<\/a>.<\/p>\n<p>I recently had the chance to work with Microsoft PFE, Mike MacGillivray, on an upgrade of some Windows certification authorities, and I want to share some information about it with you. This script has only been tested on Windows Server 2012 and later.<\/p>\n<p><strong>\u00a0 Note<\/strong>\u00a0\u00a0\u00a0This is a five-part series that includes the following posts:<\/p>\n<ul>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/2016\/02\/15\/migrate-windows-ca-from-csp-to-ksp-and-from-sha-1-to-sha-256-part-1\/?preview=true&amp;preview_id=76801&amp;preview_nonce=34b8f8d799&amp;post_format=standard\" target=\"_blank\">Migrate Windows CA from CSP to KSP and from SHA-1 to SHA-256: Part 1<\/a>\nExplore why you may need to perform this work, configure logging, and set up variables.<\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/2016\/02\/16\/migrate-windows-ca-from-csp-to-ksp-and-from-sha-1-to-sha-256-part-2\/\" target=\"_blank\">Migrate Windows CA from CSP to KSP and from SHA-1 to SHA-256: Part 2<\/a>\nBack up your certification authority (CA) and test the script.<\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/2016\/02\/17\/migrate-windows-ca-from-csp-to-ksp-and-from-sha-1-to-sha-256-part-3\/\" target=\"_blank\">Migrate Windows CA from CSP to KSP and from SHA-1 to SHA-256: Part 3<\/a>\nDelete the certificate and crypto provider so they can be rebuilt as a KSP and SHA-256 solution.<\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/2016\/02\/18\/migrate-windows-ca-from-csp-to-ksp-and-from-sha-1-to-sha-256-part-4\/\" target=\"_blank\">Migrate Windows CA from CSP to KSP and from SHA-1 to SHA-256: Part 4<\/a>\nImport keys and certificate into a KSP.<\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/2016\/02\/19\/migrate-windows-ca-from-csp-to-ksp-and-from-sha-1-to-sha-256-part-5\/\">Migrate Windows CA from CSP to KSP and from SHA-1 to SHA-256: Part 5<\/a>\nModify the registry for SHA-256.<\/li>\n<\/ul>\n<p>Before you do anything else, let\u2019s back up what you\u2019ve already got.<\/p>\n<p>Backing out of this change isn\u2019t going to be desirable, but maybe you want to test it a few times in your lab before running this script we\u2019re writing. Any way you look at it, backing up is a great idea before you do any significant change. It\u2019s not the worst idea to run this periodically, even when you\u2019re not planning to do any wild and crazy Windows CA work like we are this week.<\/p>\n<p>The first thing we\u2019re doing today is backing up your certificate database and your certificate. This might be a root certificate or an issuing CA certificate, depending on what kind of CA you\u2019re working on but the command is the same.<\/p>\n<p style=\"padding-left: 30px\">cmd.exe \/c &#8220;certutil -p $($Password) -backup $(&#8220;$Drivename\\$Foldername&#8221;)&#8221;<\/p>\n<p style=\"padding-left: 30px\">Add-LogEntry $Logpath &#8216;Saved CA database and cert&#8217;<\/p>\n<p>The backup command is pretty easy using <strong>certutil<\/strong>. I\u2019m specifying the location of where I want the backup with the <strong>\u2013backup<\/strong> parameter and giving the password with <strong>\u2013p<\/strong>. I\u2019m wrapping my variables in parentheses to help me if I\u2019ve got spaces or weird characters to worry about. Of course, I\u2019m logging this activity by using the logging function I presented yesterday.<\/p>\n<p>There are a bunch of registry settings that are going to get changed when this work is performed, so let\u2019s back those up too:<\/p>\n<p style=\"padding-left: 30px\">cmd.exe \/c &#8220;reg export hklm\\system\\currentcontrolset\\services\\certsvc\\configuration $(&#8220;$Drivename\\$Foldername&#8221;)\\CA_Registry_Settings.reg \/y&#8221;<\/p>\n<p style=\"padding-left: 30px\">Add-LogEntry $Logpath &#8216;Saved reg keys&#8217;<\/p>\n<p>This is a <strong>reg.exe<\/strong> command to export the entire configuration key for our certificate service. We\u2019re storing it in our working directory as \u201cCA_Registry_Settings.reg.\u201d<\/p>\n<p>How about your certificate revocation lists (CRLs)? You don\u2019t want to lose those either. Copy anything with a .crl extension in C:\\Windows\\System32\\certsrv\\certenroll into the backup folder:<\/p>\n<p style=\"padding-left: 30px\">Copy-Item -Path &#8216;C:\\Windows\\System32\\certsrv\\certenroll\\*.crl&#8217; -Destination &#8220;$Drivename\\$Foldername&#8221;<\/p>\n<p style=\"padding-left: 30px\">Add-LogEntry $Logpath &#8216;Copied CRL files&#8217;<\/p>\n<p>If you\u2019ve got an Enterprise CA with certificate templates, you\u2019ll want to back those up too. If you don\u2019t, this command will return a message reflecting that. There\u2019s no harm leaving it in. I\u2019m going to save the templates in Published_templates.txt in my working directory:<\/p>\n<p style=\"padding-left: 30px\">cmd.exe \/c &#8216;certutil -catemplates&#8217; | Out-File -FilePath &#8220;$Drivename\\$Foldername\\Published_templates.txt&#8221;<\/p>\n<p style=\"padding-left: 30px\">Add-LogEntry $Logpath &#8216;Got list of published cert templates&#8217;<\/p>\n<p>Now we\u2019re backed up. I\u2019m going to wrap the whole thing in a Try\/Catch block and add a little more logging information:<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/hsg-2-16-16-1.png\"><img decoding=\"async\" class=\"alignnone size-medium wp-image-76891\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/hsg-2-16-16-1-300x94.png\" alt=\"Image of code\" width=\"300\" height=\"94\" \/><\/a><\/p>\n<p>Now that we\u2019re backed up, we\u2019re ready to make some real changes to your PKI environment. Upgrading from CSP to KSP and SHA-1 to SHA-256 is a pretty involved process, but we\u2019re ready to get our hands dirty now. Join me tomorrow when I\u2019ll cover safely deleting the existing certificates and keys from your CA.<\/p>\n<p>If you are in a big hurry and want the full script, you can find it on my blog: <a href=\"http:\/\/www.workingsysadmin.com\/quick-script-share-upgrade-windows-certificate-authority-from-csp-to-ksp-and-from-sha-1-to-sha-256\/\" target=\"_blank\">Upgrade Windows Certification Authority from CSP to KSP and from SHA-1 to SHA-256<\/a>. I\u2019d sincerely recommend reading all of the posts in this series first, though, so you understand what it is you\u2019re running.<\/p>\n<p>~Thomas<\/p>\n<p>I invite you to follow me on <a href=\"http:\/\/bit.ly\/scriptingguystwitter\">Twitter<\/a> and <a href=\"http:\/\/bit.ly\/scriptingguysfacebook\" target=\"_blank\">Facebook<\/a>. If you have any questions, send email to me at <a href=\"mailto:scripter@microsoft.com\">scripter@microsoft.com<\/a>, or post your questions on the <a href=\"http:\/\/bit.ly\/scriptingforum\">Official Scripting Guys Forum<\/a>. Also check out my <a href=\"https:\/\/blogs.technet.microsoft.com\/msoms\/\" target=\"_blank\">Microsoft Operations Management Suite Blog<\/a>. See you tomorrow. Until then, peace.<\/p>\n<p><strong>Ed Wilson, Microsoft Scripting Guy<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Summary: Thomas Rayner, Microsoft Cloud &amp; Datacenter Management MVP, shows how to back up your Windows certification authority as a part of migrating from CSP to KSP and from SHA-1 to SHA-256. Hello! I\u2019m Thomas Rayner, a proud Cloud &amp; Datacenter Management Microsoft MVP, filling in for The Scripting Guy this week. You can find [&hellip;]<\/p>\n","protected":false},"author":596,"featured_media":87096,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[568],"tags":[217,56,3,63,652,45],"class_list":["post-76884","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hey-scripting-guy","tag-certificates","tag-guest-blogger","tag-scripting-guy","tag-security","tag-thomas-rayner","tag-windows-powershell"],"acf":[],"blog_post_summary":"<p>Summary: Thomas Rayner, Microsoft Cloud &amp; Datacenter Management MVP, shows how to back up your Windows certification authority as a part of migrating from CSP to KSP and from SHA-1 to SHA-256. Hello! I\u2019m Thomas Rayner, a proud Cloud &amp; Datacenter Management Microsoft MVP, filling in for The Scripting Guy this week. You can find [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/76884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/users\/596"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/comments?post=76884"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/76884\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media\/87096"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media?parent=76884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/categories?post=76884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/tags?post=76884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}