implementing new root CA
hi all,
in our environment, having root ca with following configuration rsa-ssa-pss (4096 bit) , sha1 , , windows 2008. has been configured in 2014 , certificate expires in 2024. we having 2 issuing cas 5 years validity. issuing cas expires on 2019.
now planning implement new root ca rsa (4096), sha 256 , windows 2012, planning perform below steps achive impementation impact existing users
1) implement new offline root ca
2) create certificate request issuing cas , generate certificate new root ca
3) configure certificates issuing ca
4) reenroll end entity certificates.
5) keep existing root ca till 2019 , because issuing cas certificates expire on 2019
6) create crl every year old root ca , publish till 2019.
please let me know feedback approach.
we having around 25000 users using mail encryption , know problem has been foreseen these users approach
thanks , regards,
hariharan
hi,
>>please let me know feedback approach.
we having around 25000 users using mail encryption , know problem has been foreseen these users approach
according description,you need switch new ca , don't want affecting old certificates,i suggest follow guide,it give steps need:
decommissioning old certification authority without affecting
issued certificates , switching operations new one
best regards
cartman
please remember mark replies answers if help. if have feedback technet subscriber support, contact tnmff@microsoft.com
Windows Server > Security
Comments
Post a Comment