Re: How to revoke the root CA certificate ?

From: Brian Komar (bkomar_at_nospam.identit.ca)
Date: 02/02/05


Date: Wed, 2 Feb 2005 07:15:55 -0600

In article <4200b203$0$24722$626a14ce@news.free.fr>,
yannick.beot@NOSPAM.free.fr says...
> Hi,
>
> I have a standalone certificate authority on Windows Server 2003, and I
> wonder how I can revoke the CA certificate, in the case of a
> compromission, cessation of activity,...
>
> Since it does not appear in the list of issued certificates, I don't
> know where to right-click to revoke the CA certificate.
>
> For the moment it's only to know the procedure, in case of...
>
> Thanks in advance
>
>
> Yannick Beot
>
To revoke a root, you must remove the certificate from all computer's
trusted root stores and redeploy your PKI. It is kind of a chicken and
the egg issue.

If you are revoking the root CA certificate, you want it to go on the
CRL. But what certificate is used to sign the CRL... the certificate
that you are revoking, making the CRL invalid.

Hence the importance of using good physical and logical security to
protect the root CA.

Brian



Relevant Pages

  • Re: Newbie wants to learn about PKI Server 2003......
    ... 2003 PKI Certificate Security", and have been lurking here for a bit. ... We will implement a 2 tier heirarchy, with the Root CA being offline. ... All clients that attempt revocation checking will first attempt to retrieve the CRL from the ... level below a self-signed cert, so applications that are 3280 compliant would never check the ...
    (microsoft.public.windows.server.security)
  • Help PKI installation - lots of questions !
    ... One STAND ALONE ROOT CA called SACAMX00 (SA stand for Stand Alone, ... AMERICAS Sub & CA ASIA Sub ... Client use this to find Delta CRL ... publish my CRL again even if no certificate are revoked? ...
    (microsoft.public.security)
  • Re: Help PKI installation - lots of questions !
    ... One STAND ALONE ROOT CA called SACAMX00 (SA stand for Stand Alone, ... AMERICAS Sub & CA ASIA Sub ... Client use this to find Delta CRL ... publish my CRL again even if no certificate are revoked? ...
    (microsoft.public.security)
  • Re: certificates and OWA
    ... Have you installed the root certificate on the outslide client win98 ... I suspect that is the problem and not the CRL. ... if the machines are not ...
    (microsoft.public.win2000.security)
  • Re: certificates and OWA
    ... >> Outside it is saying the certificate is issued by a company I have not ... In windows 98 it complains of the CRL. ... I install the certificate and even put it in the trusted ... >>> Is the root CA trusted on all the clients? ...
    (microsoft.public.win2000.security)

Quantcast