Solved

Certificate auto renewal, does it use the same key? signed word documents have expired

Posted on 2013-11-21
6
799 Views
Last Modified: 2013-11-22
We have auto enrolment enabled via GPO, as per this MS article http://technet.microsoft.com/en-us/library/cc731522.aspx

I can see a users certificate has recently been renewed, however all word documents signed with the old certificate have now expired!

does autoenrolment use a new key and not the same key? can anything be configured to make sure all old signed documents dont become expired?

Thanks
0
Comment
Question by:awilderbeast
  • 2
  • 2
  • 2
6 Comments
 
LVL 9

Accepted Solution

by:
Ahmed786 earned 250 total points
ID: 39665505
ITs not possible, you have to renew at certain period of time, the option you can get is either to use same pair of keys or new keys, its on you, but yes you have to renew before its expiring date is approaching.

Please go through below Microsoft article on this with proper explanation.

http://technet.microsoft.com/en-us/library/cc740209(v=ws.10).aspx

Hope this may help you.
0
 
LVL 33

Assisted Solution

by:Dave Howe
Dave Howe earned 250 total points
ID: 39665735
Renewing the key won't automagically make the signatures valid again - however, that is purely based on the current date, so there is nothing you can do (short of setting the host to ignore expired certs - really bad idea) to make the existing documents valid again.

All I can really suggest is issuing keys with a really long term (say, 25 years) - as you are issuing them yourself, that isn't going to cost you anything more, and then you have deferred having to worry about the problem for the next couple of decades :)
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 39665985
So even if the user renewed their cert before it expired all the old signed documents will have expired signatures?
0
The problems with reply email signatures

Do you wish that you could place an email signature under a reply? Well, unfortunately, you can't. That great Exchange/Office 365 signature you've created will just appear at the bottom of an email chain. What a pain! Is there really no way to solve this? Well, there might be...

 
LVL 9

Assisted Solution

by:Ahmed786
Ahmed786 earned 250 total points
ID: 39666097
Yes you are right, old documents will be marked as Expired Signatures as per my knowledge because that documents were already created some time ago and then it is expired.
0
 
LVL 33

Assisted Solution

by:Dave Howe
Dave Howe earned 250 total points
ID: 39666255
yes. the *certificate* is attached to the document as part of the signature, and cannot be separated - even if you have more certificates with the same key, the check on the document will still be on the old certificate.
0
 
LVL 1

Author Closing Comment

by:awilderbeast
ID: 39668409
THanks GUys
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now