Microsoft Certifcate Server

Does changing Certificate validty period on Cert server affect current issued certs. We want to use the following to use when issuing new certificates but don't want to invalidate any current certificates.
And does the  'certutil -renew reusekeys'  just extend current issued certs? Not experienced with CA but need to address this issue at work and we have alot of self signed certs in our departments.

certutil -setreg ca\ValidityPeriod=Years
certutil -setreg ca\ValidityPeriodUnits=100
certutil -setreg ca\RenewalValidityPeriod=Years
certutil -setreg ca\RenewalValidityPeriodUnits=100
net stop certsvc & net start certsvc

You can verify the settings by substituting "-getreg" for "-setreg"

After that, you can use the 'certutil -renew reusekeys' command to renew the certificate.
 
J1thatguyAsked:
Who is Participating?
 
Blake_1Commented:
No it does not affect currently issued certs, they will need to be re-issued or renewed.  Better to configure a proper PKI rather than using self-signed certificates.
0
 
J1thatguyAuthor Commented:
So current certs will still be valid but in order to take advantage of the new certificate life span I need to reissue the certs?
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.