Re: Automatically Renewing User Certificates from Inhouse CA?

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 03/25/05


Date: Thu, 24 Mar 2005 21:41:44 -0600

There is no way to automatically renew certificates in Windows 2000. You
will have to come up with a plan to have the users renew or obtain a new
certificate before their certificate expires. Windows 2003 Enterprise CA
when installed on Windows 2003 Enterprise Server allows the use of version 2
templates that can automatically enroll and renew user certificates. You can
use a Windows 2003 Enterprise CA in a Windows 2000 domain if you first
upgrade the forest schema. Only Windows XP Pro domain client computers can
use autoenrollment however. I believe you can also modify the registry on a
Windows 2000 CA in order to extend the life of the user certificates out to
two years for those issued after the registry mod. --- Steve

<mvanzwieten@gmail.com> wrote in message
news:1111587372.520638.141270@l41g2000cwc.googlegroups.com...
> Hi Everyone,
>
> I'm running a Win2k CA inhouse tied directly into Active Directory. In
> order to make use of EAP/TLS over VPN, I've logged onto local user's
> laptops, and downloaded user certificates for them from the CA webpage
> onto their laptops, and they use these certs when connecting through
> the VPN.
>
> The issue is this... The certificates are only good for 1 year. They
> do not renew themselves when they expire, and basically lock the person
> out from even using EAP/TLS over VPN after they expire.
>
> In order to get them working again, we have to manually browse over to
> the CA webpage, and download a new user cert all over again, deleting
> the old one that still sitting there, expired.
>
> Is there anyway to automatically make these user certs renew, or
> possibly force a renewal of that user cert on that machine?
>
> I would appreciate your advice! :)
>
> Thank you,
> Mike
>



Relevant Pages

  • Win2003 CA Cert Renewal
    ... Windows Server 2003 Certification Authority ... RootCA offline, Subordinate enterprise CA (signed ... Do I have to renew all client certificates (e.g. stored ...
    (microsoft.public.windows.server.general)
  • MS CA Certificate Renewal
    ... Windows Server 2003 Certification Authority ... RootCA offline, Subordinate enterprise CA (signed ... Do I have to renew all client certificates (e.g. stored ...
    (microsoft.public.security)
  • Re: MS CA Certificate Renewal
    ... > Windows Server 2003 Certification Authority ... > Windows XP SP1 Clients ... > Do I have to renew all client certificates (e.g. stored ...
    (microsoft.public.security)
  • [NT] Windows File Protection Arbitrary Certificate Chain Vulnerability
    ... Beyond Security would like to welcome Tiscali World Online ... Windows File Protection will trust any digital signature whose certificate ... chain is rooted at any one of the Trusted Root Certification Authorities. ... chains but also as valid Root CA's for code signing certificates. ...
    (Securiteam)
  • Re: How to fix broken security in Windows 2000?
    ... explicitly identify the missing certificates using SFC or some other tool. ... it turns out Windows 2000 doesn't support that feature after ... all W2K machines have the problem seems to be holding up (and I have not yet ...
    (microsoft.public.windowsupdate)