Answer the question
In order to leave comments, you need to log in
Is it possible to renew the certificate of a subordinate CA without losing the validity of certificates already issued by it?
Greetings comrades!
Actually the situation. The domain network has the following PKI structure:
by coincidence, the first two CAs were lost forever, while their functions are performed by subordinate CAs of another site, but! As you can see from the figure, they have a warning about the expiration of the certificate. Accordingly, you need to request a new certificate from the Root CA.
after requesting a certificate from the Root CA:
1. Will the certificates that have already been issued to computers and users remain valid? (I plan to request for the old pair of keys)
2. Will the already issued certificate be updated, or will a new certificate be issued and the old certificate revoked?
I read the update manuals, it was not entirely clear about the fate of already issued certificates. I realized that when generating a certificate from a new key pair, it will be necessary to revoke the old ones (again, it is not entirely clear whether they will be revoked after the new ones are issued, or the new ones will be received after the revocation).
PS A system has been deployed on the network that, by the validity of the certificate, allows the PC to enter the local network, as soon as the certificate ceases to be valid, the PC drops out of the network. Therefore, after revoking old certificates without issuing new ones, the system automatically turns all PCs into a pumpkin
Answer the question
In order to leave comments, you need to log in
In general, the issue was resolved. Requested a certificate from the root CA using the old key pair. The request was made through the Certification Center snap-in.
By the way, some computers automatically changed the certificate (rather, it just automatically requested a new one after the expiration of the old one, just after the center certificate was renewed), but some computers remained with the old certificate (these computers made a request before updating the certificate of the subordinate CA). To assign them an updated certificate "handles", and not wait for a second request from them, you need to go to the snap-in
"Certification Authority" -> Unsuccessful requests, in the "Status Code" field there will be a message stating that the certificate for the computer was not issued due to the issue period, which is longer than the validity period of the certificate itself (I don’t remember the exact description, the issuance template should be "Computer " or "Machine"). Select all requests with this code, and in the context menu select: All tasks -> Issue. After that, an updated certificate will be issued
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question