Click here to get back home

change ca certifiactes' subject name

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
change ca certifiactes' subject name Jan Mönnich 09-21-2005
Posted by Jan Mönnich on September 21, 2005, 12:36 pm
Please log in for more thread options
hi folks,

we need to renew the ca certificate and we want to change the subject
name of the certificate at the same time. we tried to install a new
certificate with a modified subject name. the ca displayed an error that
the common name of the submitter does not match the name of the
current configuration.

the reason we want to do that is a planned migration from an old
structure to a new one. is there any way to change a ca certificates'
subject name and keeping all issued certificates?

thanks!
jan mönnich


Posted by Brian Komar [MVP] on September 21, 2005, 5:45 am
Please log in for more thread options
says...
> hi folks,
>
> we need to renew the ca certificate and we want to change the subject
> name of the certificate at the same time. we tried to install a new
> certificate with a modified subject name. the ca displayed an error that
> the common name of the submitter does not match the name of the
> current configuration.
>
> the reason we want to do that is a planned migration from an old
> structure to a new one. is there any way to change a ca certificates'
> subject name and keeping all issued certificates?
>
> thanks!
> jan mönnich
>
No. When you renew a CA certificate you are signing the request with the
old CA certificate (thus requiring the same name)

If you want to switch names, you need to do a phased migration. You keep
the old CAs up to sign CRLs, but remove all ability to issue
certificates:
- standalone CA: ensure all requests are pended and you reject all
requests
- enterprise CA: Do not make any certificate templates available.

Deploy new CAs with the desired names and then deploy from the new CAs
all certificates

Brian


Similar ThreadsPosted
How to add a subject alternative name to a request? October 2, 2008, 9:59 am
Ceritifcate Services Autoenrollment Subject Name Format April 23, 2006, 4:33 pm
CA certificate template custom subject name format January 9, 2007, 1:49 pm
CA certificate template custom subject name format January 16, 2007, 12:11 am
Win2003 PKI : certreq.exe using 'special' subject fields October 2, 2007, 10:22 am
Is it possible to change computer sid on AD? February 8, 2006, 3:32 pm
change user in cmd March 3, 2006, 8:34 am
Registry change June 19, 2006, 11:30 am
Making a Change to SCW GPO December 19, 2006, 12:07 pm
Change Administrator SID September 21, 2008, 11:15 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap