Re: Question on chnaging the expiration date of certificates

From: Miha Pihler [MVP] (mihap-news_at_atlantis.si)
Date: 03/12/05


Date: Sat, 12 Mar 2005 00:10:45 +0100

Hi,

If I understand you correctly, your Standalone RootCA is valid for 10 years
and you have one Standalone Subordinate CA that is valid for 1 year.

In this case, your subordinate CA will only be able to issue certificates
valid for maximum 1 year since its own certificate is valid for that period
of time. You can't issue certificates with longer date of validity then its
issuing CA certificate.

What you need to do is change the validity period on your RootCA to value
that you desire (e.g. 8 years) and then re-issue certificate for your
Subordinate CA. Once this is done and you change validity period on your
Subordinate CA you should be able to issue certificates on your subordinate
CA for your users with validity period that is longer then 1 year.

Once the certificate is issued, you can't change its validity time. If you
would edit the certificate it would become invalid (digital signature would
not match).

I hope this helps.

-- 
Mike
Microsoft MVP - Windows Security
"Kavi" <Kavi@discussions.microsoft.com> wrote in message 
news:7F4D84C3-0BEA-4C75-9734-74951C4EF16D@microsoft.com...
> Hi ,
> I was trying to change the default expiration date of certificates from 1
> year to a different value on a standlone Sub-ordinate CA server.
> I used the information from the Microsoft article Q254632.
>
> When I initiallythe installed the Standalone sub-ordinate CA server , the
> validity dates were determined by the parent CA ( Set to 1 year )
> ( Standalone RootCA , validity set to 10 years ).
>
> But I would like to change it to 8 years from the default setting of 1 
> year.
>
> After following the suggestion in the document Q254632 , the user certs 
> and
> the CA cert still has the same validity of 1 year . The CA service was
> started and stopped and the system was alos started .
>
> Any idea of what could be wrong.
>
> Kavi
> 


Relevant Pages

  • Win2003 PKI : certreq.exe using special subject fields
    ... The second is a standalone (no enterprise) ... The certificate is send to the subordinate CA for signing. ...
    (microsoft.public.windows.server.security)
  • Re: renew CA certificate
    ... > When I renew the CA certificate, I can`t specify the period of validity. ... It depends on whether the CA is a root CA or a subordinate CA. ... parent CA to define the subordinate CA's validity period. ...
    (microsoft.public.windows.server.security)
  • Re: AD CS 2008 & Subordinate CA Validity Periods?
    ... The validity period of issued certificate is defined at the issuing CA. ... you cannot define it at the subordinate CA in the capolicy.inf file. ...
    (microsoft.public.windows.server.security)
  • Re: Need advice for CA Model
    ... The certificate chain was issued by ... We are logging in to get a certificate from the subrdinate standalone CA. ... > The root CA must be trusted on all the clients that will enroll to the ... >> subordinate, this was planned to be used for issuing users from outside ...
    (microsoft.public.win2000.security)
  • Re: Windows 2003 CA 0x80092013
    ... > get CA services working but now I get these errors when trying to issue ... > Certificate The certificate validity period will be shorter than the ... > period is longer than the maximum certificate validity period allowed by ... This could be for any or all of the CAs in the CA hierarchy ...
    (microsoft.public.security)