I am very new to ADCS, and have a challenge to migrate our old Tire-2 PKI to SHA-256. As we were suggested to setup a parallel SHA-2 CA, I am not greeting any idea, how to go ahead with it, I can create a offline Root CA with SHA-2, but then how do I publish it to my current environment, Also how to stop using SHA-1 certs after sometime. Tried searching blogs and articles, , I was looking any step by step document, didnt find any suitable one, any suggestion would be appreciated.
Thanks