implementing new root CA


hi all,

in our environment, having root ca  with following configuration rsa-ssa-pss (4096 bit) , sha1 , , windows 2008. has been configured in 2014 , certificate expires in 2024.  we having 2 issuing cas 5 years validity. issuing cas expires on 2019.

now planning implement new root ca rsa (4096), sha 256 , windows 2012, planning perform below steps achive impementation impact existing users

1) implement new offline root ca

2) create certificate request issuing cas , generate certificate new root ca

3) configure certificates issuing ca

4) reenroll end entity certificates.

5) keep existing root ca till 2019  , because issuing cas certificates expire on 2019

6) create crl every year old root ca , publish till 2019.

please let me know feedback approach.

we having around 25000 users using mail encryption , know problem has been foreseen these users approach

thanks , regards,

hariharan

hi,

>>please let me know feedback approach.

we having around 25000 users using mail encryption , know problem has been foreseen these users approach

according description,you need switch new ca , don't want affecting old certificates,i suggest follow guide,it give steps need:

decommissioning old certification authority without affecting
issued certificates , switching operations new one

https://blogs.technet.microsoft.com/pki/2012/01/27/decommissioning-an-old-certification-authority-without-affecting-previously-issued-certificates-and-then-switching-operations-to-a-new-one/


best regards
cartman
please remember mark replies answers if help. if have feedback technet subscriber support, contact tnmff@microsoft.com



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file