Link to home
Start Free TrialLog in
Avatar of SimonBrook
SimonBrook

asked on

Root CA corrupted. built new one. Can I point intermediate CA at this and not break issued certs?

Hello,

Recently we found out that we needed to change the cryptographic HASH algorithm on our CA's to SHA256. Unfortunately our offline Root CA (rootca01) was corrupt and therefore the PKI chain is broken. We have spun up a new Root CA (rootca02) and are wondering whether we can point the intermediate ca (subca01) at rootca2 without breaking the certs currently issued somehow?

What is the best practice for this scenario? Server 2012.

Thanks,
ASKER CERTIFIED SOLUTION
Avatar of Mahesh
Mahesh
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial