Jump to content

Recommended Posts

Posted

We have an offline Root CA and online subordinate CA used for internal PKI - the subordinates certificate (i.e the one issued from the Root CA) expires in about 10 months but I want to renew early.

 

If I renew it now (creating a new certificate for the subordinate CA) and deploy it using GPO (and manually for other systems that have it) am I right in thinking that any certificate issued against the old (but still valid) subordinate CA will still be valid?

 

In other words, if I miss something and it doesn't get the new subordinate CA cert will the old certs continue to be valid (until their expiry date of course!)

 

That's my plan, renew, deploy and then I have a window to find anywhere that has the subordinate CA cert installed that might have been done manually

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...