Re: Extend Root CA cert lifetime



You can extend it by defining the renewal validity period in the capolicy.inf
There is a best practices whitepaper available at www.microsoft.com/pki
This is also covered in my PKI book (referenced on the same page)
Brian

"tman" <tony.barrett@xxxxxxxxxx> wrote in message news:4FB21733-5E8B-44EA-97D3-E3F321CA520A@xxxxxxxxxxxxxxxx
We have a local root CA that has a lifetime on its issuing certificate that runs up until mid 2010. The cert lifetime is currently 5 years. Our subordinate issuing CA issues most of the certs onsite, but that can only issue certs up to the lifetime of the root CA. Although this works in most instances ok, I now realise as we're only issuing internally, a much longer lifetime on the root CA (and subsequently the sub CA) would have been better. I'd like to extend the lifetime of the main root CA to 15 years, and the sub CA to 10 years without causing any interruption to the cert issuing process.

Although I know how to renew the issuing CA certificates, I can't see a way to extend the lifetime, so when I next renew the root CA cert, it will be valid for 15 years and not 5. I'd like to do this by renewing (and not re-requesting) root certs as well (and keep the same key-pair).

Both CA's run Win2k3 Enterprise.

Is this possible, and if so, could someone explain (or point me in the direction of a document which does) how to do this.

TIA

.



Relevant Pages

  • Re: Extend Root CA cert lifetime
    ... Renew a second time with the second key pair ... I've located the capolicy.inf file on the root ca, and modified the renewalvalidityperiodunits value from 5 to 15. ... I renewed the root CA certificate, but the lifetime is still the same! ... All other cert issuing policies seem to work fine. ...
    (microsoft.public.windows.server.security)
  • Re: Extend Root CA cert lifetime
    ... I've located the capolicy.inf file on the root ca, and modified the renewalvalidityperiodunits value from 5 to 15. ... I renewed the root CA certificate, but the lifetime is still the same! ... All other cert issuing policies seem to work fine. ...
    (microsoft.public.windows.server.security)
  • Re: Trusted CA question
    ... The IIS box's fully qualified name is ... > don't really need a "trusted" verisign cert to assure anonymous ecommerce ... I just need SSL turned on to protect some data transmissions ... > for being the root and one for the site, and in the IIS manager I attached ...
    (microsoft.public.win2000.security)
  • Re: Change validatiy period of a Root certificate
    ... should not have either an AIA or a CDP URL in it" But when I go to install ... my subordinate stand alone CA it asks me for a Root CA to get it's cert from. ... I picks up my newly created standalone Root CA. ... certificate, copying the certificate to removable media and then installing ...
    (microsoft.public.security)
  • Re: Authenticate Computer account using PEAP MS-CHAPv2 on IAS 2k
    ... using a test root CA. IAS has a valid cert from the ... and clients have the root CA cert installed in the Local Computer Trusted ... authentication. ...
    (microsoft.public.internet.radius)