Solved

Root Authority Certificate

Posted on 2014-11-19
3
171 Views
Last Modified: 2014-11-23
I noticed when installing a new SSL certificate on one of my servers yesterday that my Domain Root Authority certification was expiring next month. When I looked into how to renew it, I noticed that the server that issued it has been delete from the domain by one of my old IT staff.

I do have an new server running the Active Directory Certificate Service however the certificate does not show therefore I cannot renew it.

Can somebody assist with some instructions on what the the best way forward is.

Thanks
0
Comment
Question by:GlennCameron
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 33

Accepted Solution

by:
Dave Howe earned 500 total points
ID: 40453673
Just build a new one; it doesn't really matter if you have two.

I am assuming you have the two-level thing going on - a root, then issuing CAs (signed by the root) on a couple of domain servers)

So, first step, set up a new primary root; you can use a MS CA for that, but to be honest, that's overkill for what you need, I usually just set one up in xca for the infrequent use you will have for one.  Give it 40 years, and add this to domain policy so it can be pushed out to all hosts.

Next, after you let that settle in for a couple of days, generate a CSR from each of your subordinate CAs, and use XCA to sign them. a good length of time for these is 6 years.

Finally, copy the offline root a few times, and put the copies someplace safe (if you use an MS CA for your offline root, build that as a virtual machine and after you are done with it, copy that VM a few times (note that a vm will be some GB in size, while the XCA db will only be a few MB at most)
0
 

Author Comment

by:GlennCameron
ID: 40456068
Thanks for your reply. We have only one server (which is a DC) running Active Directory Certificate Services. On the machines server manager the ‘Enterprise PIK\CA name’ node it has the following in the list view.

Untitled.png
My understanding is that this is read off the AD and this should mean that I am good now through to 2020. Is that correct? Any other suggestions?

Thanks
0
 
LVL 33

Expert Comment

by:Dave Howe
ID: 40456882
that's how it looks to me - best bet though is to look at the certificate chain for any issued certificate; that is a one-stop-shop to check the validity and expiry of the leaf cert, intermediate, and root.
0

Featured Post

Free eBook: Backup on AWS

Everything you need to know about backup and disaster recovery with AWS, for FREE!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question