Chapter 4. Certificate Manager
Configuration
Configuring cloning.
Table 4.2. General Subsystem Configuration Links
4.6. CA Certificate Reissuance
When a CA signing certificate expires, all certificates signed with the CA's corresponding signing key
become invalid. End entities use information in the CA certificate to verify the certificate's authenticity.
If the CA certificate itself has expired, applications cannot chain the certificate to a trusted CA.
Reissuing a CA certificate involves issuing a new CA certificate with a new name, public and private
key material, and validity period. All certificates issued by the old CA certificate, including those that
have not yet expired, must be replaced by the new CA certificate.
Begin planning the CA certificate reissuance before installing any Certificate System managers,
and consider the ramifications the planned procedures may have for extensions, policies, and other
aspects of the PKI deployment.
NOTE
Correct use of extensions, for example the authorityKeyIdentifier extension, can
affect the transition from an old CA certificate to a new one.
4.7. Changing the Rules for Issuing Certificates
The restrictions on the certificates issued are set by default after the subsystem is configured. These
include:
• Whether certificates can be issued with validity periods longer than the CA signing certificate. The
default is to disallow this.
• The serial number range the CA is able to use to issue certificates.
• The signing algorithm used to sign certificates.
Subordinate CAs have constraints for the validity periods, types of certificates, and the types of
extensions which they can issue. It is possible for a subordinate CA to issue certificates that violate
these constraints, but a client authenticating a certificate that violates those constraints will not accept
that certificate. Check the constraints set on the CA signing certificate before changing the issuing
rules for a subordinate CA.
To change the certificate issuance rules, do the following:
1. Open the Certificate System Console.
pkiconsole https://hostname:port/ca
2. Select the Certificate Manager item in the left navigation tree of the Configuration tab.
112
Section
Chapter 19, Configuring the Certificate System
for High Availability
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?
Questions and answers