Re: change ca certifiactes' subject name

From: Brian Komar [MVP] (bkomar_at_nospam.identit.ca)
Date: 09/21/05


Date: Wed, 21 Sep 2005 05:45:56 -0500

In article <OyPrJhpvFHA.3124@TK2MSFTNGP12.phx.gbl>, jan.moennich@gwdg.de
says...
> hi folks,
>
> we need to renew the ca certificate and we want to change the subject
> name of the certificate at the same time. we tried to install a new
> certificate with a modified subject name. the ca displayed an error that
> the common name of the submitter does not match the name of the
> current configuration.
>
> the reason we want to do that is a planned migration from an old
> structure to a new one. is there any way to change a ca certificates'
> subject name and keeping all issued certificates?
>
> thanks!
> jan mönnich
>
No. When you renew a CA certificate you are signing the request with the
old CA certificate (thus requiring the same name)

If you want to switch names, you need to do a phased migration. You keep
the old CAs up to sign CRLs, but remove all ability to issue
certificates:
- standalone CA: ensure all requests are pended and you reject all
requests
- enterprise CA: Do not make any certificate templates available.

Deploy new CAs with the desired names and then deploy from the new CAs
all certificates

Brian



Relevant Pages

  • Re: Windows 2000 Certificate Services - Help Request (Understanding and operation).
    ... > produced as a result of requests from the subordinate server. ... > I have exported a certificate and imported it into Outlook 2002. ... > is capable of sending signed messages and recognising signed ...
    (microsoft.public.win2000.security)
  • Re: Cannot request computer certificate.
    ... Just to clarify, the cerutil - ping is working, not the certificate ... I am sure that the fact that the web requests work and the mmc ...
    (microsoft.public.windows.server.security)
  • Re: Windows 2000 Certificate Services - Help Request (Understanding and operation).
    ... It>> does not show the certificates issued or revoked or failed which were>> produced as a result of requests from the subordinate server. ... It>> is capable of sending signed messages and recognising signed>> messages sent from a different account as signed. ... I get a>> warning that there is a problem with the other persons certificate and>> that it is not trusted. ...
    (microsoft.public.win2000.security)
  • Re: Validity period of certificates is not accepted anymore
    ... The feature of reducing the lifetime of a> certificate is great! ... The life time of the certificate is> accepted by the policy module, but it states that there are> no SMIME capability extensions set. ... There used to be an extension for> this, but right now Netscape / Mozilla requests lack it. ...
    (microsoft.public.platformsdk.security)
  • Adding certificate chain to signed CMC request?
    ... Following the "Creating Certificate Requests Using the Certificate ... When I compared a signed request from the CertSrv site (using ... that my requests do not include the whole certificate chain. ...
    (microsoft.public.platformsdk.security)