Configure Role for ADCS Failover

  1. In the Failover Cluster Management snap-in, right-click Role and select Configure Role.

  2. On the Before you Begin page, click Next.

  3. From the role list, select Generic Service and click Next.

465f83b2-d177-4dde-b814-92b61daf567f.jpg


"Select Role" Window

  1. From the service list, select Active Directory Certificate Services and click Next.

  2. On the Client Access Point page, enter the role name in the Name field and click Next.

82c0eea1-446b-4a31-bfa8-9e08f419b8b8.jpg


"Client Access Point" Window

  1. Select the disk storage that is still mounted to the node and click Next.

  2. Configure a shared registry hive, select the Add button, enter SYSTEM\CurrentControlSet\Services\CertSvc and click OK.

706e958f-fd14-48f8-91e9-d45450947e94.jpg


"Replicate Registry Settings" Window

  1. Click Next on the Confirmation page.

  2. Click Finish to complete the failover role configuration.

  3. Open the Failover Cluster Manager and verify that the newly created Roles Status is in the Running state and Green.

  4. The AD CS Failover was configured successfully. At this stage, you can move the certification authority between all nodes.