Re: Certificate Renewal questions

From: Krish Shenoy[MSFT] (kshenoy_at_online.microsoft.com)
Date: 01/21/04

  • Next message: Guangxi Wu: "Re: Reversed issuer name returned by X509Certificate.GetIssuerName()"
    Date: Wed, 21 Jan 2004 14:27:33 -0800
    
    

    In the case of request with same key you have the option of selecting
    Advanced page where you can choose a different certificate template whereas
    for renew with same key you cannot choose the template.

    -- 
    Krish Shenoy[MSFT]
    This posting is provided "AS IS" with no warranties, and confers no rights.
    "Steve" <stephen.h.price@intel.com> wrote in message
    news:bumrub$dc2$1@news01.intel.com...
    > I need some help in understanding the mechanics of certificate renewal.  I
    > have two questions:
    >
    > In the Certificates MMC console, when I right-click on a cert and go to
    All
    > Tasks I see the following tasks:
    > Request with new key
    > Request with same key
    > Renew with new key
    > Renew with same key
    >
    > I've tried both a Request with same key and a Renew with same key on a
    valid
    > certificate.  The results seem to be the same.  In both cases I get a cert
    > with a different serial number so the results seem to be identical.
    >
    > 1. What is the difference between the Request task and the Renew task?
    >
    > When I right-click on an expired cert and go to All Tasks, I get the same
    > list of tasks as above, however, when I try to Renew with same key, I get
    > the following error:
    >
    > "The certification authority denied the request.  A required certficiate
    is
    > not within its validity period when verifying against the current system
    > clock or the timestamp in the signed file."
    >
    > A Request with same key does go through successfully.
    >
    > 2. Why does  'Renew with same key' not work for an expired certificate
    while
    > a 'Request with same key' does work?
    >
    > Thanks,
    >
    > Steve
    >
    >
    

  • Next message: Guangxi Wu: "Re: Reversed issuer name returned by X509Certificate.GetIssuerName()"

    Relevant Pages

    • Certificate Renewal questions
      ... I need some help in understanding the mechanics of certificate renewal. ... In the Certificates MMC console, when I right-click on a cert and go to All ... Request with same key ... Renew with same key ...
      (microsoft.public.platformsdk.security)
    • Certificate Renewal
      ... I need some help in understanding the mechanics of certificate renewal. ... In the Certificates MMC console, when I right-click on a cert and go to All ... Request with same key ... Renew with same key ...
      (microsoft.public.win2000.security)
    • Re: How to renew a certificate programmicaly
      ... policy restriction is "Enrollment Agent" and that the "old certificate" does ... "X number of authotized signatures" and "Subject details supply in request". ... >> Now, After I succeed in creating a renew request, I have a new problem ...
      (microsoft.public.platformsdk.security)
    • Re: Using Server 2003 to sign Sonicwall VPN certificate
      ... Sonicwall 3.1 network appliance. ... signing the internally generated certificate on the Sonicwall. ... When I try to "Submit new request" on my online issuing CA, ... The request does not contain a certificate template ...
      (microsoft.public.security)
    • Re: Certificate Authority Error
      ... How are you generating the request? ... tempalte information. ... certificate template as an example. ... > The request contains no certificate template information 0x80094801 ...
      (microsoft.public.windows.server.security)