Re: CA certificate renwal - three level PKI structure



There really should not be any issues.
The catch though is that you could have certificates that were issued the day before the enterprise CA was renewed that will need to validate the previous enterprise CA certificate.
What you can do to protect against revocation checking issues is to issue a new CRL at the 2nd tier (before you remove it) that is good for at least 1 year.
Make sure you publish the 1yr+ crl at the relevant CDP locations (and keep the old 2nd CA certificate at the AIA locations) for at least a year

This should allow for a smooth transition

Brian

"Martin" <zanny@xxxxxxxxxxxx> wrote in message news:%23V3x5zuLIHA.5328@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

My organisation have Enterprise CA in the AD domain. Its certificate will expire within 1 year from now, so we need to renew it. It is the "lowest" CA in tree level PKI structure (higher level Root and Sub are standalone CAs).
Renewal event is an occasion to simplify our PKI structure. We don't really need two higer level CAs, two level should be enough. The best solution is to recertify Enterprise CA with Root CA not Sub CA as it was done before. Has anyone did it before ? Is there any danger that PKI services in domain will fail and become ususable ?

Thank you.

Martin.




.



Relevant Pages

  • RE: Upgrade Standard CA to an Enterprise CA
    ... Do you mean you want to migrate the stand-alone CA to Enterprise CA? ... Back up the certificate database, the CA certificate, and the CA private ... 8.Select Preserve existing certificate database to use the old database. ...
    (microsoft.public.security)
  • CA certificate renwal - three level PKI structure
    ... My organisation have Enterprise CA in the AD domain. ... in tree level PKI structure (higher level Root and Sub are standalone CAs). ... Renewal event is an occasion to simplify our PKI structure. ... really need two higer level CAs, ...
    (microsoft.public.windows.server.security)
  • Re: Isolation of the Root CA
    ... If you want to put your Enterprise CA behind a firewall, ... practice article on that? ... >> An Enterprise CA can not be an offline CA. ... >> standalone root CA and use it to issue a certificate for an Enterprise CA ...
    (microsoft.public.win2000.security)
  • Re: EFS and Certificate Services
    ... > I created a Enterprise Root CA with a Enterprise Subordinate CA for issuing ... An Enterprise Root CA computer cannot be offline. ... I check the thumbprint of the file and the certificate which matched. ... The best practice is to issue the certificates *before* any encryption ...
    (microsoft.public.win2000.security)
  • Re: W2K3 3-tier CA Implementation
    ... No matter what environment you are in, install a standalone ROOT CA. ... based on the standalone subordinate CA. ... I agree with issuing CAs being enterprise CAs. ... You do not use a certificate tempalte for the ...
    (microsoft.public.security)