Removing a Subordinate CA


first background:

  • os: server 2008 r2 std
  • i have 1 enterprise root ca on server1 (brand new, standalone server, no issues)
  • i have 1 subordinate ca on server2
  • server2 dc

i remove ca role server2 , maintain it's status domain controller only.  this leave me 1 enterprise root ca on server1.

i'm in process of reading through following articles , trying in test environment:

http://blogs.technet.com/b/pki/archive/2012/01/27/steps-needed-to-decommission-an-old-certification-authority-without-affecting-previously-issued-certificates-and-then-switching-all-operations-to-a-new-certification-authority.aspx

http://support.microsoft.com/kb/889250

does have experience this?  my main concern is: happens certificates issued server2?  any input appreciated.

1) certificates invalid after 2/2015 , should not accepted application anymore - need replacement ca issue new certificates these clients before. 2/2015 absolute latest time can use certificates, provided valid crls available until (see 2)).

2) certificate paths built fetching ca certificates in http or ldap urls in certificates (extension aia), revocation lists retrieved crl distribution points - http and/or ldap urls (extension cdp). if remove these servers or files/objects published on them or if crl published there expired certificates not validated before feb. 02. keeping distribution points means need make sure @ least 1 of urls in certificates still accessible , valid ca certs. or crls published these urls.

creating long-lived crl make sure applications validating certificates kept happy if ca had been retired , cannot publish new crls anmore.

3) advise against doing unless 100% sure don't need certificates anymore or replace them ones ca immediately. revoking of them means can't validate them anymore, , large crls can cause issues applications.

caveat: creating 'eternal ca' means cannot reasonably revocation in future - should plan replacing certificates typically need revoke (lost smartcards, e.g.)

elke



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS