Renaming a Certificate Root authority

Renaming a Certificate Root authority

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Renaming a Certificate Root authority Bill 06-28-2006
Posted by =?Utf-8?B?QmlsbA==?= on June 28, 2006, 5:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I need to rename the certificate root, the "issued by" field on the
certificate. Is this possible with Windows 2000, or Win2k3? If so, would
the certificates previously issued by that CA be invalidated?

Thank you,

Bill


Posted by Steven L Umbach on June 29, 2006, 6:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You can't change issued certificates and you can't rename a Certificate
Authority. You can create a new Certificate Authority with the name you
need. You can run into problems with "old" certificates if the
computers/applicaions no longer trusts the CA that issued them and when
Certificate Revocation Lists are no longer available. Creating a new CA that
is a subordinate CA to an existing CA with the name you want would be a
relatively safe way to go if that could be a possibility. --- Steve

http://www.microsoft.com/windowsserver2003/technologies/pki/default.mspx ---
Public Key Infrastructure for Windows Server 2003


>I need to rename the certificate root, the "issued by" field on the
> certificate. Is this possible with Windows 2000, or Win2k3? If so, would
> the certificates previously issued by that CA be invalidated?
>
> Thank you,
>
> Bill
>



Posted by =?Utf-8?B?QmlsbA==?= on June 29, 2006, 9:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thank you, that helps very much. I think I'll try creating a subordinate.

"Steven L Umbach" wrote:

> You can't change issued certificates and you can't rename a Certificate
> Authority. You can create a new Certificate Authority with the name you
> need. You can run into problems with "old" certificates if the
> computers/applicaions no longer trusts the CA that issued them and when
> Certificate Revocation Lists are no longer available. Creating a new CA that
> is a subordinate CA to an existing CA with the name you want would be a
> relatively safe way to go if that could be a possibility. --- Steve
>
> Public Key Infrastructure for Windows Server 2003
>
>
> >I need to rename the certificate root, the "issued by" field on the
> > certificate. Is this possible with Windows 2000, or Win2k3? If so, would
> > the certificates previously issued by that CA be invalidated?
> >
> > Thank you,
> >
> > Bill
> >
>
>
>

Posted by Steven L Umbach on June 29, 2006, 11:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
OK. If you are going to create a subordinate issuing CA be sure to configure
the certificate templates so that only the CA you want is issuing
certificates to the computers/users that need the new issued by field. You
can configure which certificate templates a CA will issue in the Certificate
Authority Management Console mmc snapin and selecting which CA to
manage. --- Steve


> Thank you, that helps very much. I think I'll try creating a subordinate.
>
> "Steven L Umbach" wrote:
>
>> You can't change issued certificates and you can't rename a Certificate
>> Authority. You can create a new Certificate Authority with the name you
>> need. You can run into problems with "old" certificates if the
>> computers/applicaions no longer trusts the CA that issued them and when
>> Certificate Revocation Lists are no longer available. Creating a new CA
>> that
>> is a subordinate CA to an existing CA with the name you want would be a
>> relatively safe way to go if that could be a possibility. --- Steve
>>
>>
>> ttp://www.microsoft.com/windowsserver2003/technologies/pki/default.mspx
>> ---
>> Public Key Infrastructure for Windows Server 2003
>>
>>
>> >I need to rename the certificate root, the "issued by" field on the
>> > certificate. Is this possible with Windows 2000, or Win2k3? If so,
>> > would
>> > the certificates previously issued by that CA be invalidated?
>> >
>> > Thank you,
>> >
>> > Bill
>> >
>>
>>
>>



Posted by Alun Jones on June 29, 2006, 8:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>I need to rename the certificate root, the "issued by" field on the
> certificate. Is this possible with Windows 2000, or Win2k3? If so, would
> the certificates previously issued by that CA be invalidated?

Not as such, no.

However, you will be unable to sign any revocation lists.

It is generally not a useful thing, to rename a certificate root.

Alun.
~~~~
[Please don't email posters, if a Usenet response is appropriate.]
--
Texas Imperial Software | Find us at http://www.wftpd.com or email
23921 57th Ave SE | alun@wftpd.com.
Woodinville WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers.
Fax/Voice +1(425)807-1787 | Try our NEW client software, WFTPD Explorer.



Similar ThreadsPosted
Root certificate authority no longer added to client machines December 15, 2006, 8:15 am
Clients no longer pick up the Root CA as a trusted root authority June 6, 2006, 6:59 pm
what type of certificate authority? June 16, 2005, 4:08 pm
Certificate Authority type June 16, 2005, 6:01 pm
Problem with certificate authority January 27, 2006, 9:03 am
Certificate Authority (CA) - Failover Possible? February 24, 2006, 8:20 pm
Microsoft Certificate Authority June 14, 2006, 8:25 am
Problem in Certificate Authority February 23, 2007, 4:09 am
Certificate Authority Settings May 22, 2007, 3:46 pm
Certificate Authority Configuration February 25, 2008, 11:47 pm

The site map in XML format XML site map

Contact Us | Privacy Policy