Ca Certificate Reissuance; Changing The Rules For Issuing Certificates - Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION:
Table of Contents

Advertisement

Chapter 4. Certificate Manager
Configuration
Configuring cloning.
Table 4.2. General Subsystem Configuration Links

4.6. CA Certificate Reissuance

When a CA signing certificate expires, all certificates signed with the CA's corresponding signing key
become invalid. End entities use information in the CA certificate to verify the certificate's authenticity.
If the CA certificate itself has expired, applications cannot chain the certificate to a trusted CA.
Reissuing a CA certificate involves issuing a new CA certificate with a new name, public and private
key material, and validity period. All certificates issued by the old CA certificate, including those that
have not yet expired, must be replaced by the new CA certificate.
NOTE
Correct use of extensions, for example the authorityKeyIdentifier extension, can
affect the transition from an old CA certificate to a new one.

4.7. Changing the Rules for Issuing Certificates

The restrictions on the certificates issued are set by default after the subsystem is configured. These
include:
• Whether certificates can be issued with validity periods longer than the CA signing certificate. The
default is to disallow this.
• The serial number range the CA is able to use to issue certificates.
• The signing algorithm used to sign certificates.
Subordinate CAs have constraints for the validity periods, types of certificates, and the types of
extensions which they can issue. It is possible for a subordinate CA to issue certificates that violate
these constraints, but a client authenticating a certificate that violates those constraints will not accept
that certificate. Check the constraints set on the CA signing certificate before changing the issuing
rules for a subordinate CA.
To change the certificate issuance rules, do the following:
1. Open the Certificate System Console.
pkiconsole https://hostname:port/ca
2. Select the Certificate Manager item in the left navigation tree of the Configuration tab.
120
Section
Chapter 20, Configuring the Certificate System
for High Availability

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Table of Contents