Solved

SBS Small Business Server Self Signed Certificate Renewal Period

Posted on 2014-11-30
3
339 Views
Last Modified: 2014-12-05
Hi All,

I have noticed a change in behaviour for SBS Self Signed Certificates recently, specifically relating to the renewal period.

From memory, they used to renew for two years, however three recent renewals done on our client SBS servers have only renewed for slightly over two months. This has happened on both SBS 2008 and SBS 2011 servers, fully patched and updated to date.

Obviously having to remember to renew client server certificates every few months will become a hassle!

Has anyone else seen this and/or know why the renewal period has changed?

Thanks & Seasons Greetings To All from Melbourne, Australia!
0
Comment
Question by:lexrx
  • 2
3 Comments
 
LVL 57

Accepted Solution

by:
Cliff Galiher earned 500 total points
ID: 40473000
SBS sets up a CA at the time it is installed. Then the "self signed" certificate is issued as a leaf when the wizard is run. While the leaf is issued for two years, the root (created when the OS is first installed) is a bit longer so it doesn't have to be renewed as often and so that a new cert doesn't need to be installed on clients when the leaf is renewed.. Based on what you are describing, my suspicion is that the root is about to expire, which would make the window between leaf renewal and root expiration only a couple months. It isn't something you'll need to keep doing every few months though. Once renewed, the root won't expire again for a few years (much like the leaf) so you'll be back to normal.
0
 

Author Comment

by:lexrx
ID: 40484193
Hi Cliff, thanks for the explanation. Is there command or GUI available to show the expiration status of the root?

Thanks and regards, Brad.
0
 

Author Closing Comment

by:lexrx
ID: 40484194
Answered on point and totally resolves my query.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Microsoft  Partnership 1 81
SBS 2011 - migration to Exchange 2016 5 217
SBS 2008 cannot logon remotely 7 55
gpupdate /force gives errors and warnings that never correct 17 62
If you are a user of the discontinued Microsoft Office Accounting 2008 (MSOA) and have to move to a new computer running Windows 8, you will be unhappy to discover that it won't install.  In particular, Microsoft SQL Server 2005 Express Edition (SSE…
You may have discovered the 'Compatibility View Settings' workaround for making your SBS 2008 Remote Web Workplace 'connect to a computer' section stops 'working around' after a Windows 10 client upgrade.  That can be fixed so it 'works around' agai…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question