Re: How to install a new Enterprise Root Certificate Authority to replace an old one?

From: Brian Komar (bkomar_at_nospam.komarconsulting.com)
Date: 04/24/04

  • Next message: Brian Komar: "Re: How to install a new Enterprise Root Certificate Authority to replace an old one?"
    Date: Sat, 24 Apr 2004 16:15:27 -0500
    
    

    Answers inline...
    Brian

    In article <uH94S0RKEHA.1120@TK2MSFTNGP11.phx.gbl>,
    umetricsdev@umetrics.com says...
    > Thanks again,
    >
    > Sadly, that solution isn't really practical for me (I've already setup the
    > new DC with a different name and moved lots of stuff from the old DC to it,
    > and besides I don't want to keep the old name around! :=) ).
    >
    > So back again to my original questions:
    >
    > Can I install a second Root Enterprise CA in the domain in parallel with the
    > old CA?
    Yes, this is just another root CA in the organization, that will use the
    same certificate templates available in the Configuration naming
    context. When you install the new root CA, information will be added to
    the AIA, CDP and Certificate Services containers in the following
    location: CN=Public Key
    Services,CN=Services,CN=Configuration,ForestRootDomainLDAPName

    > Or must I uninstall the first CA first?
    The order does not really matter except that you should clean the old CA
    references out of the Configuration NC. What I recommend is to use the
    PKi Health Tool from the 2003 Resource Kit (pkiview.msc). You can then
    view each container, and delete the old certs and CRLs from the
    Configuration NC.

    >
    > And in both cases, how does it affect my clients, or rather, how do I make
    > the inpact as little as possible? (These questions are more elaborated in
    > my original post in this thread).
    >

    The impact will be that all old certs are dead/gone/toast. You should
    plan for the immediate deployment of required certificates. Once you
    uninstall or remove the old CA, all certificate validation will break
    down at the next CRL publish interval for the old CA.

    > / Erik
    >
    <snip>


  • Next message: Brian Komar: "Re: How to install a new Enterprise Root Certificate Authority to replace an old one?"

    Relevant Pages

    • Re: Certificate authorities and firewalls
      ... Make the SA Root certificate and CRLs outside of the firewall ... extension to include an externally accessible location where the CRLs and CA ... If the firewall does not allow the SARootCA machine to publish to these two ...
      (microsoft.public.win2000.security)
    • Key Recovery Agent with no access to Root CA CRL
      ... we are using an outside third-party Root CA ... certificate" could not be validated when the user requested a certificate ... the client machines and noticed that although the certificate itself is ... that if we manually installed the Root CA CRLs on the user's machine, ...
      (microsoft.public.windows.server.active_directory)
    • Re: Signtool doesnt add entire chain when signing files
      ... you only need to ensure that the intermediate certificates are included in the signature so that the client can build a chain to the root. ... The root needs to be installed as a trusted root certificate on the client in order for the client to trust the certificate. ... Given that you don't have any intermediate certificates, it doesn't matter or not whether they are included in the signature so it should not matter if there is any difference between the wizard mode and the command line tool mode. ...
      (microsoft.public.platformsdk.security)
    • Re: Schannel CertificateChainValidation failing
      ... I am not fully up to speed with certs (root, end entity, ... valid Windows trusted root cert. ... You've enabled certificate revocation checking, and the validation code ...
      (microsoft.public.platformsdk.security)
    • Re: Certificate chain issue with Ent Sub Ca & stand alone Root CA
      ... certificate and I get a "Cannot verify certificate chain. ... revocation because the revocation server was offline. ... the root ca? ... Online>>> Online Enterprise Subordinate CA ...
      (microsoft.public.windows.server.security)