Two tier Certificate Services deployment with root CA in stand-a-lone and issuing CA in domain.
I have created my Root CA, it is set to expire in 20 years on my stand-a-lone CS, Windows 2008 Enterprise R2 SP1. I have sent a request over from my Issuing CS, also running Windows 2008 R2 SP1. The Root CA signs the certificate, and I export it to a file. However, when I open the Cert information is says it will expire in a year. I don't want my signed certificate to expire for many years, but am not sure where to change that? I have not imported this cert into my issuing CA or have I assigned it to my root ca yet.
September 13th, 2011 12:25am

You need to adjust the validity period of issued certificates om your Root CA, using the commands below will give you 10 years for all issued certificates certutil.exe -setreg ca\ValidityPeriodUnits 10 certutil.exe -setreg ca\ValidityPeriod "Years" /Hasain
Free Windows Admin Tool Kit Click here and download it now
September 13th, 2011 7:43am

note that you must restart certificate services after setting change.My weblog: http://en-us.sysadmins.lv PowerShell PKI Module: http://pspki.codeplex.com Windows PKI reference: on TechNet wiki
September 13th, 2011 8:23am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics