Offline Root CA Deleted!!!
while decommissioning on 150 or virtual machines approval, new hire mistakenly deleted vm our offline enterprise root ca (it powered off on year) , unfortunately, seem there no recoverable backup.
understand microsoft pki enough know actual root certificate still valid , in ad until expires, should ok functionality wise. my query is: can build new root ca , issue new certificate subordinates/issuing cas or going have rebuild entire pki structure? what process follow?
-alan
your pki continue work until crl root ca expires, shorter period of time validity of root ca itself. can use pkiview.msc on issuing ca, right click enterprise pki , select manage ad containers. on revocation list tab can see root ca's crl file , expiration date.
you can create new root ca , renew subordinate new root. when that, want renew subordinate same key (do not create new key). way, existing certificates issued subordinate ca chain new root.
mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. co-founder of revocent (revocent.com) , certaccord product offers linux certificate enrollment microsoft ca. connect mark @ https://www.pkisolutions.com
Windows Server > Security
Comments
Post a Comment