Solved

Certificate Authority - Extending the Validity Period of a pre-installed CA

Posted on 2010-08-31
8
1,280 Views
Last Modified: 2012-05-10
I am currently running Windows SBS 2008 (not that I can percieve its that much different from 2003) and the Certificate Authority is already installed on it with the default 5 year validity period.

I would like to extend the validity period for the ROOT CA as high as it will go, but because it is already installed I cannot appear to do this by the wizard, and the certreq utility isn't the most friendly of commands.

How can I extend the validity period of the ROOT CA, and also increase the exipiry periods of all of the certifcates it will issue?

Thanks x
0
Comment
Question by:sterlingdev
8 Comments
 
LVL 6

Expert Comment

by:radnbne
ID: 33566544
I believe you need to revoke and recreate the certificate in order to extend it.
0
 
LVL 5

Expert Comment

by:DanMar
ID: 33566895
Have a look if a renewal in the "Fix my network" wizard works otherwise try editing the capolicy.inf file and adjusting validity periods.
0
 

Author Comment

by:sterlingdev
ID: 33570686
I know I would need to revoke and recreate the root CA, but when you do it just sticks to the same 5 year default. Is there a way of changing it?
0
 
LVL 5

Expert Comment

by:DanMar
ID: 33574703
Hi, the other option I mentioned was "editing the capolicy.inf file and adjusting validity periods" - you may have success with this.
0
Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

 

Author Comment

by:sterlingdev
ID: 33574762
Capolicy.inf does not exist.
0
 
LVL 5

Accepted Solution

by:
DanMar earned 500 total points
ID: 33576886
0
 

Author Comment

by:sterlingdev
ID: 33577180
Thank you, yes this seems to work, by creating the CAPolicy.INF file and saving it into the root of the WINDOWS directory with the following contents...

[certsrv_server]
RenewalValidityPeriodUnits=99
RenewalValidityPeriod=years

I have regenerated the CA Root cert and now has an expiry of 2109!

Thanks
0
 

Expert Comment

by:McKuser
ID: 33747489
This didin't work for me.  Must I restart any service?
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now