Re: Validity period of certificates is not accepted anymore

From: David Cross [MS] (dcross_at_online.microsoft.com)
Date: 11/25/04


Date: Thu, 25 Nov 2004 05:13:12 -0800

The CA policy module will always truncate the validity of an issued cert to
be within the lifetime of its own validity period. You must renew the CA
with a longer lifetime to avoid this.

-- 
David B. Cross [MS]
--
This posting is provided "AS IS" with no warranties, and confers no rights.
Top Whitepapers:
Auto-enrollment whitepaper: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/autoenro.mspx
Best Practices for implementing Windows Server 2003 PKI: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws3pkibp.mspx
Troubleshooting Certificate Status and Revocation whitepaper: 
http://www.microsoft.com/technet/security/topics/crypto/tshtcrl.mspx
Windows Server 2003 web enrollment and troubleshooting guide: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
Windows Server 2003 web enrollment and troubleshooting guide: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
"Sebastian Rieger" <sebastian.rieger@gwdg.de> wrote in message 
news:OQHm5Vk0EHA.2600@TK2MSFTNGP09.phx.gbl...
> Hi All,
>
> we're using microsoft windows certificate services to deploy certificates 
> to our customers. Using a Windows 2003 Enterprise Edition Server we were 
> able to use certificate templates to map the current needs of our users to 
> certificates. The policy module complained about the validity period of 
> the certificate being to long from the begining of the ca usage, but 
> accepted the request (reducing the validity period of the certificate to 
> the end of life of our ca certificate). Today the policy modules suddenly 
> refused the certificates complaining about the validity period of the 
> certificate. Our ca certificate is valid up to May 2005 - can we solve 
> this problem without renweing our ca certificate? can the limit be 
> increased via registry, or do we need to code our own policy module.
>
> Thanks in advance,
>
> Sebastian Rieger 


Relevant Pages

  • Re: Windows 2003 CA 0x80092013
    ... > get CA services working but now I get these errors when trying to issue ... > Certificate The certificate validity period will be shorter than the ... > period is longer than the maximum certificate validity period allowed by ... This could be for any or all of the CAs in the CA hierarchy ...
    (microsoft.public.security)
  • Re: certutil -sign equivalent
    ... The validity written into a certificate is determined by two factors, ... validity period defined on the cert template ... If you want to have control over validity period per request, ...
    (microsoft.public.platformsdk.security)
  • Re: certutil -sign equivalent
    ... "Oriane" wrote in message ... > | The validity written into a certificate is determined by two factors, ... > | validity period defined on the cert template (If the CA is Enterprise ... > | If you want to have control over validity period per request, ...
    (microsoft.public.platformsdk.security)
  • Re: renew CA certificate
    ... > When I renew the CA certificate, I can`t specify the period of validity. ... It depends on whether the CA is a root CA or a subordinate CA. ... parent CA to define the subordinate CA's validity period. ...
    (microsoft.public.windows.server.security)
  • Validity period of certificates is not accepted anymore
    ... we're using microsoft windows certificate services to deploy ... Server we were able to use certificate templates to map the current ... The policy module complained about ... but accepted the request (reducing the validity period ...
    (microsoft.public.platformsdk.security)