Offline Root CA Deleted!!!


hello, 

while decommissioning on 150 or virtual machines approval, new hire mistakenly deleted vm our offline enterprise root ca (it powered off on year) , unfortunately, seem there no recoverable backup.  

understand microsoft pki enough know actual root certificate still valid , in ad until expires, should ok functionality wise.  my query is: can build new root ca , issue new certificate subordinates/issuing cas or going have rebuild entire pki structure?  what process follow?

-alan

your pki continue work until crl root ca expires, shorter period of time validity of root ca itself. can use pkiview.msc on issuing ca, right click enterprise pki , select manage ad containers. on revocation list tab can see root ca's crl file , expiration date.

you can create new root ca , renew subordinate new root. when that, want renew subordinate same key (do not create new key). way, existing certificates issued subordinate ca chain new root.


mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. co-founder of revocent (revocent.com) , certaccord product offers linux certificate enrollment microsoft ca. connect mark @ https://www.pkisolutions.com



Windows Server  >  Security



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607