Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

PKI 2012 R2 - Subordinate Enterprise CA Receives Reduced Expiration Period in SubCA Certificate: 2 yrs VS 5 yrs

$
0
0

Hi All,

The PKI infrastructure includes the following elements:

  1. All CAs are Windows Server 2012 R2 member servers.
  2. Online Enterprise Root CA: RootCA [RSA (4096 bit)].
  3. Enterprise Subordinate CA SubCA01 and SubCA02 are both directly subordinated toRootCA.
  4. CAs Details
    4.1. RootCA: RSA, 4096 bit. Valid for 20 years.
    Subordinate Certification Authority certificate template (SubCA Certificate Template) has 5 years of validity. 
    4.2. SubCA01 and SubCA02: RSA, 4096 bit. Security certificate is based on the SubCA Certificate Template.
    But the certificate is valid for 2 years, although it is using the SubCA Certificate Template which sets the validity of 5 years.
  5. The re-pro of the brand new test domain with 2-tier PKI infrastructure generated the same issue.

Questions:

  1. How to enforce that the SubCA-based certificate is valid for 5 years on SubCA01 andSubCA02?
  2. What is the potential cause of the under provisioning of the certificate validity period? Or where to look for the investigation?
  3. Is it possible to renew with the same key the certificate for the SubCA, but with longer validity period? Should any other certificates be re-issued except for the SubCA certificate for the subordinate CAs?
  4. Is there a way to configure the SubCA template so that the SubCA template based certificate is issued for the enterprise new subordinate CA with the expected validity period?
  5. Can the SubCA certificate be renewed automatically and how to configure it if possible?
  6. Can the SubCA certificate validity period be longer than the validity period of the Root CA?

Tons of thanks in advance for your great help and attention!!!


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>