S/MIME Certificate renewal in W2K3 - EX2K3 infrastructure

S/MIME Certificate renewal in W2K3 - EX2K3 infrastructure

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
S/MIME Certificate renewal in W2K3 - EX2K3 infrastructure Andreas.Konrad 10-06-2008
Posted by =?Utf-8?B?QW5kcmVhcy5Lb25yYWQ= on October 6, 2008, 2:13 am
If you were  Registered and logged in, you could reply and use other advanced thread options


Hi all,



I've implemented secure messaging as described here:
http://www.msexchange.org/tutorials/Email_Security_with_Exchange_2003.html



In my GPO I configured Autoenrollment and checked the two boxex "Renew
expired certificates..." and "Update certificates..."

The renewal period in my template is 6 weeks and the certificate expires
after one year.



Now I'm wondering why it is necessary to keep the old certificate in my
certificate store after getting a new one within the renewal period. If I
remove the old one I am not able to decrypt mails being encrypted by using my
old public key.

I thought the private key remains the same if the certificate is renewed and
I would be able to decrypt mails that are encrypted with both public keys -
the old and the new one.



Can anyone arrange my ideas? :-)



Thanks a lot

Andy



Similar ThreadsPosted
PKI Question - User Certificate Renewal February 21, 2008, 4:56 pm
PKI User Certificate on Smart Card auto renewal ? August 29, 2007, 11:22 am
C# and SMIME Decryption July 13, 2006, 7:03 pm
Public Key Infrastructure September 12, 2005, 2:40 am
PKI - Manual Enroll - Auto Renewal - Possible? May 22, 2008, 1:05 am
US-Cert Update on New Attacks on Computer Infrastructure August 28, 2008, 8:12 am
Renewal request for public cert on a Win2003 server w/o IIS installed September 7, 2006, 5:20 pm
Microsoft Executive Circle Webcast: Security360 with Mike Nash: Building a Secure, Connected Infrastructure with Digital Certificates April 18, 2006, 7:25 am
FYI - Windows Update agent (client) infrastructure update coming soon July 3, 2008, 6:57 pm
MS05-051 on W2K3 October 18, 2005, 12:16 pm

The site map in XML format XML site map

Contact Us | Privacy Policy