Re: Root CA Certificate vs Client Cert Expiration

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 05/02/05

  • Next message: Steven L Umbach: "Re: Do I need to use the SysKey utility to enhance the security?"
    Date: Mon, 2 May 2005 10:39:47 -0500
    
    

    Thanks Brian. That was very helpful as is your book. :) --- Steve

    "Brian Komar (MVP)" <bkomar@nospam.identit.ca> wrote in message
    news:MPG.1cdf6e167cda895b98969b@msnews.microsoft.com...
    > In article <umhsAXaTFHA.3308@TK2MSFTNGP14.phx.gbl>, n9rou@nospam-
    > comcast.net says...
    >> Hi Brian.
    >>
    >> Thanks for elaborating and I have a question for you if you have the
    >> time.
    >>
    >> In what cases, if any, does it make sense to renew a certificate with the
    >> same private key for a client certificate?? I know it is a less secure
    >> option. I was messing around with renewal options the other day and found
    >> that for at least EFS and e-mail using outlook express that if I renewed
    >> a
    >> certificate with the same private key that the new certificate could not
    >> be
    >> used to decrypt EFS files or emails that were encrypted with the "old"
    >> certificate that had the same public key/private key. What is the
    >> mechanism
    >> preventing such? Does the application also check for serial number,
    >> thumbprint, or time stamp to make a determination if the
    >> certificate/private
    >> key can be used?? I think I read somewhere sometime that renewing a
    >> certificate with the same private key was mostly a decision based on
    >> performance in that it saved cpu cycles because a new key pair did not
    >> have
    >> to be generated and maybe that is the only reason to use it? Thanks for
    >> any
    >> help. --- Steve
    >>
    >>
    >><snip>
    > For client certificates, I would rarely renew with the same key. The
    > only circumstance that I could think of would be if a certificate
    > template did not have the correct configuration, and you change the
    > template, wanting to renew the certificate to have the correct
    > information in the certificate. Not very likely (especially if you
    > test).
    >
    > Now with CA certificates, that is a different story. For CA
    > certificates, the best practices guide (and my book) recommend renewing
    > with the same key pair at half of the CA certificate's lifetime. This
    > ensures that the remaining certificate lifetime remaining for the CA
    > certificate does not constrain the lifetime of the certificates it
    > issues. Then, at the full lifetime of the original cert, renew with a
    > new key pair.
    >
    > I have not done extensive testing with renewing with the same key pair,
    > so I really cannot offer much of a response for your other questions. It
    > really depends on the app. I know that for encryption, EFS stores the
    > thumbprint of the active cert in the registry. I did not believe that
    > it was the case for decryption, but I have never tested your scenario.
    >
    > HTH,
    > Brian


  • Next message: Steven L Umbach: "Re: Do I need to use the SysKey utility to enhance the security?"

    Relevant Pages

    • Re: Running in France
      ... >>> federation which requires one when you subscribe, so maybe any club ... >>> French federations). ... >>> on having a certificate, ... >>> I, the undersigned, Dr Proctor, certify that Mr Aleguzzler, Brian ...
      (uk.rec.running)
    • Re: Windows 2000 Certificate server---->2003
      ... Thanks Brian. ... securing and safeguarding Windows 98 and Windows NT computers available from ... Can only issue version 1 certificates using Automatic Certificate Request ...
      (microsoft.public.security)
    • Re: solaris 9 certification upgrade
      ... Brian Leung wrote: ... i want to upgarde to Solaris 9 certificate. ... I have always been leary of just upgrading. ... what did your first certificate bring you? ...
      (comp.unix.solaris)
    • Re: Are CSPs in a Certificate Template hard coded?
      ... Presumably you can actually enrol succesfully now as the correct CSP ... As Brian says, providing you are using the Certificate Templates MMC ...
      (microsoft.public.windows.server.security)
    • Re: Birth certificate update
      ... and it shows that it was picked up in NJ, so I guess it's up to Fedex now! ... Clay ... Thanks Brian, there is another thread here I started asking if anyone on this forum new someone in that office. ... Incidentally they are quoting now average 55 days for Certificate copies, ...
      (rec.travel.cruises)