Click here to get back home

CA certificate renwal - three level PKI structure

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
CA certificate renwal - three level PKI structure Martin 11-24-2007
Posted by Martin on November 24, 2007, 5:54 pm
Please log in for more thread options
Hi,

My organisation have Enterprise CA in the AD domain. Its certificate will
expire within 1 year from now, so we need to renew it. It is the "lowest" CA
in tree level PKI structure (higher level Root and Sub are standalone CAs).
Renewal event is an occasion to simplify our PKI structure. We don't
really need two higer level CAs, two level should be enough. The best
solution is to recertify Enterprise CA with Root CA not Sub CA as it was
done before. Has anyone did it before ? Is there any danger that PKI
services in domain will fail and become ususable ?

Thank you.

Martin.




Posted by Brian Komar on November 24, 2007, 7:01 pm
Please log in for more thread options
There really should not be any issues.
The catch though is that you could have certificates that were issued the
day before the enterprise CA was renewed that will need to validate the
previous enterprise CA certificate.
What you can do to protect against revocation checking issues is to issue a
new CRL at the 2nd tier (before you remove it) that is good for at least 1
year.
Make sure you publish the 1yr+ crl at the relevant CDP locations (and keep
the old 2nd CA certificate at the AIA locations) for at least a year

This should allow for a smooth transition

Brian

> Hi,
>
> My organisation have Enterprise CA in the AD domain. Its certificate will
> expire within 1 year from now, so we need to renew it. It is the "lowest"
> CA in tree level PKI structure (higher level Root and Sub are standalone
> CAs).
> Renewal event is an occasion to simplify our PKI structure. We don't
> really need two higer level CAs, two level should be enough. The best
> solution is to recertify Enterprise CA with Root CA not Sub CA as it was
> done before. Has anyone did it before ? Is there any danger that PKI
> services in domain will fail and become ususable ?
>
> Thank you.
>
> Martin.
>
>
>


Similar ThreadsPosted
Application Level Security January 3, 2006, 9:18 am
File Level Blocking May 16, 2006, 2:22 pm
Domain Function Level Change. January 2, 2008, 1:12 pm
Applying Security Template to Every User's Folder Structure January 10, 2007, 11:31 pm
Limiting the ability to create folders in network filing structure November 16, 2005, 12:56 pm
Looking for best practices for setting up secure user home directory file structure October 6, 2006, 8:47 pm
"No Certificate Templates Could Be Found" Error Message When User Requests Certificate from CA Web Enrollment Pages September 21, 2006, 1:31 pm
Create Certificate Request for Windows2003 certificate authority without using website March 22, 2006, 8:07 am
Problem when requesting a certificate to IIS server (certificate web enrollment) October 4, 2005, 9:50 am
Restrict AD-User to one X509 Certificate per Certificate template? July 12, 2007, 12:18 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap