[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

Microsoft Certifcate Server

Posted on 2010-09-18
2
Medium Priority
?
986 Views
Last Modified: 2012-05-10
Does changing Certificate validty period on Cert server affect current issued certs. We want to use the following to use when issuing new certificates but don't want to invalidate any current certificates.
And does the  'certutil -renew reusekeys'  just extend current issued certs? Not experienced with CA but need to address this issue at work and we have alot of self signed certs in our departments.

certutil -setreg ca\ValidityPeriod=Years
certutil -setreg ca\ValidityPeriodUnits=100
certutil -setreg ca\RenewalValidityPeriod=Years
certutil -setreg ca\RenewalValidityPeriodUnits=100
net stop certsvc & net start certsvc

You can verify the settings by substituting "-getreg" for "-setreg"

After that, you can use the 'certutil -renew reusekeys' command to renew the certificate.
 
0
Comment
Question by:J1thatguy
2 Comments
 
LVL 5

Accepted Solution

by:
Blake_1 earned 2000 total points
ID: 33710503
No it does not affect currently issued certs, they will need to be re-issued or renewed.  Better to configure a proper PKI rather than using self-signed certificates.
0
 

Author Comment

by:J1thatguy
ID: 33710587
So current certs will still be valid but in order to take advantage of the new certificate life span I need to reissue the certs?
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
With just a little bit of  SQL and VBA, many doors open to cool things like synchronize a list box to display data relevant to other information on a form.  If you have never written code or looked at an SQL statement before, no problem! ...  give i…
This video tutorial shows you the steps to go through to set up what I believe to be the best email app on the android platform to read Exchange mail.  Get the app on your phone: The first step is to make sure you have the Samsung Email app on your …
Suggested Courses

607 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question