Renew Subordinate CA certificate

Renew Subordinate CA certificate

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Renew Subordinate CA certificate =?Utf-8?B?UFQ=?= 07-16-2008
Posted by =?Utf-8?B?UFQ=?= on July 16, 2008, 8:21 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have an Enterprise CA root server and a subordinate CA server in my domain
(single domain). Both of these servers are running on Windows 2003
Enterprise edition.

I was able to obtain a subordinate CA certificate when i originally set it
up (this original sub CA certificate will expire on 2/2009). Now i would
like to renew my subordinate CA's so the expiration date will be further out
(e.g. to year 2012) so all client certificates issued by this subordinate CA
will have a longer expiration date. According to this MS article, i should be
able to renew it by right clicking on the sub CA server and select renew.

http://technet2.microsoft.com/windowsserver/en/library/4fbf053c-c0ae-4fad-a29d-1d17f04cd5fc1033.mspx?mfr=true

After the renewal request, the subordinate CA didn't get a renewed
certificate. The root CA server on the other hand did show that the new
certificate has been issued. But the subordinate server just didn't get it
no matter how many times i restarted the server.

I need help!!


Posted by =?Utf-8?B?TmVpbA==?= on July 20, 2008, 7:55 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi
I have only had limited experience with a standalone root CA, not an
enterprise root, but how about you try manually importing the certificate.

To do this on the root CA open Certification Authority snap-in.
Expand your server
Click the 'Issued Certificates' folder
Find the certificate that has been issued to your sub CA and double click it.
Click the Details tab
Click 'Copy to File'
Click Next
Select 'Cryptographic Message Syntax Standard - PKCS #7 Certificates'
Tick 'Include all certificates in the certification path if possible'
Click Next
Type a filename E.g. C:\SubCA.p7b
Click Next
Click Finish
Click OK
Click OK
Move the .p7b file to the sub CA

Open Certificate Authority on the sub CA
Right-click your server, click All Tasks > Install CA Certificate
Navigate to the .p7b file and Click Open

That may work.

Neil

"PT" wrote:

> I have an Enterprise CA root server and a subordinate CA server in my domain
> (single domain). Both of these servers are running on Windows 2003
> Enterprise edition.
>
> I was able to obtain a subordinate CA certificate when i originally set it
> up (this original sub CA certificate will expire on 2/2009). Now i would
> like to renew my subordinate CA's so the expiration date will be further out
> (e.g. to year 2012) so all client certificates issued by this subordinate CA
> will have a longer expiration date. According to this MS article, i should be
> able to renew it by right clicking on the sub CA server and select renew.
>
>
http://technet2.microsoft.com/windowsserver/en/library/4fbf053c-c0ae-4fad-a29d-1d17f04cd5fc1033.mspx?mfr=true
>
> After the renewal request, the subordinate CA didn't get a renewed
> certificate. The root CA server on the other hand did show that the new
> certificate has been issued. But the subordinate server just didn't get it
> no matter how many times i restarted the server.
>
> I need help!!
>

Similar ThreadsPosted
How to remove the Subordinate Enteprise CA expired certificate April 3, 2007, 9:38 am
Urgent - Subordinate Ceritication Authority Certificate Expired April 2, 2007, 2:28 pm
Can not renew root ca February 18, 2008, 11:27 am
root ca/subordinate ca October 3, 2007, 9:11 am
subordinate ent CAs don't publish certs to AD after Win 2k3 SP1 July 23, 2005, 1:00 pm
PKI question, trusting subordinate CA January 1, 2006, 4:24 am
Change from Root CA to Subordinate CA February 2, 2006, 11:36 am
Stand-alone vs Enterprise subordinate CA? March 9, 2007, 12:23 pm
Question on Enterprise Subordinate CA configuration April 2, 2007, 12:21 pm
Windows 2000 subordinate CA ---> 2003 July 22, 2008, 5:54 pm

The site map in XML format XML site map

Contact Us | Privacy Policy