Solved

Root Authority Certificate

Posted on 2014-11-19
3
166 Views
Last Modified: 2014-11-23
I noticed when installing a new SSL certificate on one of my servers yesterday that my Domain Root Authority certification was expiring next month. When I looked into how to renew it, I noticed that the server that issued it has been delete from the domain by one of my old IT staff.

I do have an new server running the Active Directory Certificate Service however the certificate does not show therefore I cannot renew it.

Can somebody assist with some instructions on what the the best way forward is.

Thanks
0
Comment
Question by:GlennCameron
  • 2
3 Comments
 
LVL 33

Accepted Solution

by:
Dave Howe earned 500 total points
ID: 40453673
Just build a new one; it doesn't really matter if you have two.

I am assuming you have the two-level thing going on - a root, then issuing CAs (signed by the root) on a couple of domain servers)

So, first step, set up a new primary root; you can use a MS CA for that, but to be honest, that's overkill for what you need, I usually just set one up in xca for the infrequent use you will have for one.  Give it 40 years, and add this to domain policy so it can be pushed out to all hosts.

Next, after you let that settle in for a couple of days, generate a CSR from each of your subordinate CAs, and use XCA to sign them. a good length of time for these is 6 years.

Finally, copy the offline root a few times, and put the copies someplace safe (if you use an MS CA for your offline root, build that as a virtual machine and after you are done with it, copy that VM a few times (note that a vm will be some GB in size, while the XCA db will only be a few MB at most)
0
 

Author Comment

by:GlennCameron
ID: 40456068
Thanks for your reply. We have only one server (which is a DC) running Active Directory Certificate Services. On the machines server manager the ‘Enterprise PIK\CA name’ node it has the following in the list view.

Untitled.png
My understanding is that this is read off the AD and this should mean that I am good now through to 2020. Is that correct? Any other suggestions?

Thanks
0
 
LVL 33

Expert Comment

by:Dave Howe
ID: 40456882
that's how it looks to me - best bet though is to look at the certificate chain for any issued certificate; that is a one-stop-shop to check the validity and expiry of the leaf cert, intermediate, and root.
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
OfficeMate Freezes on login or does not load after login credentials are input.
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question