seb89 Posted April 4, 2024 Posted April 4, 2024 Hello. I've had a look around and can't seem to find another example in our situation and just wanting some clarity as to what I need to do. Our Guardian CA certificate will expire in 23 days. This certificate is signed by our CA and this isn't set to expire until 2031. This is the certificate that gets pushed out to all clients. Therefore do I just need to create a new Guardian CA certificate and leave the main CA one and not need to distribute any new certificates to clients? Many thanks!
ibpalle Posted April 4, 2024 Posted April 4, 2024 No. You need to create a new CA. The original seems no longer to be present. Create an entirely new CA, download and distribute that to the clients. Then once done, set it as default CA. Old and new can be on the client systems at the same time.
tom_newton Posted April 4, 2024 Posted April 4, 2024 If the long-lived CA is the one pushed to your clients, a new CA signed by that will do fine.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now