Need to renew sub CA cert for longer validity period than default of 5 years


i have windows 2008 domain root ca (online) , sub ca.  my root cert 5 years , sub 2 years.  i'd renew root 20 , sub 10 , issue 5 year smartcard certs.  so, i created capolicy.inf file , renewed root ca , took new validity period of 20 years.  did same on subca capolicy.inf setting of 10 years no matter period 5 years everytime gen cert.  used same capolicy.inf , did ‘certutil –setreg validityperiodunits 10.  think related subordinate certificate template on ca set 5 years , not editable.  if duplicate template, change 10 , try issue template, new template not in list on root.  available issue on subca.year validity.  if duplicate template , try issue template on rootca, edited template doesn’t show in list of templates issued.  ideas?

below article might hepful.

http://forums.techarena.in/active-directory/1290288.htm

http://support.microsoft.com/kb/254632

previous discussion.

http://social.technet.microsoft.com/forums/en-us/winserversecurity/thread/3310ac17-9f86-49a2-ade7-bdf3cc1fc153/

 

regards  


awinish vishwakarma| my blog

disclaimer: posting provided as-is no warranties or guarantees , confers no rights.



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file