Certificate Chain


hi

i have a scenario have an issuing ca has issued on 20,000 odd number of end user certificates. issuing ca is signed root 'a'. business requirement issuing ca signed root 'b', of course new cps

my plan generate certificate request file using the existing key pair , dn information of issuing ca. signed by root 'b' not have re-issue 20,000 odd certificates. instead publish re-signed issuing ca across end user systems which the certificate chain able build upto root 'b'.

note - root 'b' public ca hence trusted end user systems.

i request know if approach feasible. in advance.

cheers
sanurajan.

do need have issued certificates being under the rootb tree? isn't feasible scenario create new issuingca start issuing new certs new users/services without revoking existing one?

if not, sure public rootb considered authority 20000 published certificates? don't think :-)

ondrej.


Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file