Solved

Microsoft Certifcate Server

Posted on 2010-09-18
2
936 Views
Last Modified: 2012-05-10
Does changing Certificate validty period on Cert server affect current issued certs. We want to use the following to use when issuing new certificates but don't want to invalidate any current certificates.
And does the  'certutil -renew reusekeys'  just extend current issued certs? Not experienced with CA but need to address this issue at work and we have alot of self signed certs in our departments.

certutil -setreg ca\ValidityPeriod=Years
certutil -setreg ca\ValidityPeriodUnits=100
certutil -setreg ca\RenewalValidityPeriod=Years
certutil -setreg ca\RenewalValidityPeriodUnits=100
net stop certsvc & net start certsvc

You can verify the settings by substituting "-getreg" for "-setreg"

After that, you can use the 'certutil -renew reusekeys' command to renew the certificate.
 
0
Comment
Question by:J1thatguy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 5

Accepted Solution

by:
Blake_1 earned 500 total points
ID: 33710503
No it does not affect currently issued certs, they will need to be re-issued or renewed.  Better to configure a proper PKI rather than using self-signed certificates.
0
 

Author Comment

by:J1thatguy
ID: 33710587
So current certs will still be valid but in order to take advantage of the new certificate life span I need to reissue the certs?
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
In this video, viewers will be given step by step instructions on adjusting mouse, pointer and cursor visibility in Microsoft Windows 10. The video seeks to educate those who are struggling with the new Windows 10 Graphical User Interface. Change Cu…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question