Re: Updating CA

From: David Cross [MS] (dcross@online.microsoft.com)
Date: 04/01/03


From: "David Cross [MS]" <dcross@online.microsoft.com>
Date: Tue, 1 Apr 2003 06:11:24 -0800


No, renewing the CA does not invalidate anything previously issued. Renewal
will actually generate a new cert and all new issuance willbe based on the
new certs while the old cert remains in effect. I recommend renewal with
new key as a best practice.

--
David B. Cross [MS]
--
This posting is provided "AS IS" with no warranties, and confers no rights.
http://support.microsoft.com
"Neal" <neal.latham@nospam.businesslinkkent.com> wrote in message
news:036c01c2f797$0a331f00$a001280a@phx.gbl...
> Our CA currently expires on the 6th August and
> consequently any new certificates created expire on the
> 6th August as well.
>
> I have some instruction for renewing the Certificate
> Authority but my question is this.
>
> Will renewing the certificate authority invalidate the
> certificates currently in use? As I would hate to have to
> recall all our laptops back in one hit.
>
> Regards
>
> Neal Latham


Relevant Pages

  • Re: SSL and Client Authentication
    ... First I go on my client and I do a browser request from a CA, ... After issuing a cert. ... install (where I verify that this certification was installed ... > It definitely does not sound like the right way to do client certificates. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Error issuing certificates from WS03 cert svc
    ... Your problem was the removal of the revoked certificates. ... The revocation function was unable to ... The request was for <here comes specific cert subject info>. ... All certs are likewise published on the web server ...
    (microsoft.public.windows.server.security)
  • Re: User certificate question (no AD installed)
    ... > We are able to use the VPN with computer certificates without problems, ... When opening the page to request a certificate, ... web browser cert, e-mail cert and adv cert request. ... environments involves AD and ISA server. ...
    (microsoft.public.win2000.networking)
  • Re: cert authority
    ... Any chance that you can explain the reason w2k3 white papers told me to ... automatically verified the cert, where now it can't verify it automatically. ... Open the certificates console for your user and check Trusted Root ... Now that I moved it into my 2k AD, it doesn't seem to trust the cert. ...
    (microsoft.public.win2000.active_directory)
  • Re: How can I act as a Certificate Authority (CA) with openssl ??
    ... then putting that on a web site. ... problem if you were selling certificates using "Mickey Mouse" as the ... The browser maker and cert orgs like this since ...
    (sci.crypt)