Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Root Authority Certificate

Posted on 2014-11-19
3
Medium Priority
?
189 Views
Last Modified: 2014-11-23
I noticed when installing a new SSL certificate on one of my servers yesterday that my Domain Root Authority certification was expiring next month. When I looked into how to renew it, I noticed that the server that issued it has been delete from the domain by one of my old IT staff.

I do have an new server running the Active Directory Certificate Service however the certificate does not show therefore I cannot renew it.

Can somebody assist with some instructions on what the the best way forward is.

Thanks
0
Comment
Question by:GlennCameron
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 33

Accepted Solution

by:
Dave Howe earned 2000 total points
ID: 40453673
Just build a new one; it doesn't really matter if you have two.

I am assuming you have the two-level thing going on - a root, then issuing CAs (signed by the root) on a couple of domain servers)

So, first step, set up a new primary root; you can use a MS CA for that, but to be honest, that's overkill for what you need, I usually just set one up in xca for the infrequent use you will have for one.  Give it 40 years, and add this to domain policy so it can be pushed out to all hosts.

Next, after you let that settle in for a couple of days, generate a CSR from each of your subordinate CAs, and use XCA to sign them. a good length of time for these is 6 years.

Finally, copy the offline root a few times, and put the copies someplace safe (if you use an MS CA for your offline root, build that as a virtual machine and after you are done with it, copy that VM a few times (note that a vm will be some GB in size, while the XCA db will only be a few MB at most)
0
 

Author Comment

by:GlennCameron
ID: 40456068
Thanks for your reply. We have only one server (which is a DC) running Active Directory Certificate Services. On the machines server manager the ‘Enterprise PIK\CA name’ node it has the following in the list view.

Untitled.png
My understanding is that this is read off the AD and this should mean that I am good now through to 2020. Is that correct? Any other suggestions?

Thanks
0
 
LVL 33

Expert Comment

by:Dave Howe
ID: 40456882
that's how it looks to me - best bet though is to look at the certificate chain for any issued certificate; that is a one-stop-shop to check the validity and expiry of the leaf cert, intermediate, and root.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In 2017, ransomware will become so virulent and widespread that if you aren’t a victim yourself, you will know someone who is.
The recent Petya-like ransomware attack served a big blow to hundreds of banks, corporations and government offices The Acronis blog takes a closer look at this damaging worm to see what’s behind it – and offers up tips on how you can safeguard your…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question