RE: CA Client Certificates only expire in one years time



Hi Roman,

If this was installed as an Enterprise CA this is normal. Enterprise CAs
get the validity dates of the certificates from the certificate templates
which in v1 templates cannot be modified. v2 Templates can be modified but
require Enterprise Edition of Windows Server for issuance. If you look
closely in the article you mentioned this is discussed as well.

"For certificates that are issued by Enterprise CAs, the validity period is
defined in the template that is used to create the certificate. Windows
2000 and Windows Server 2003 Standard Edition do not support modification
of these templates. Windows Server 2003 Enterprise Edition supports Version
2 certificate templates that can be modified. The validity period defined
in the template applies to all certificates issued by any Enterprise CA in
the Active Directory forest. One exception is the Subordinate CA
certificate templates. There is no validity period defined in this
template. Instead, the CA's registry validity period determines the
validity period of the Subordinate CA certificate. A certificate that is
issued by a CA is valid for the minimum of the following periods of time:

the registry validity period that is noted earlier in this article.
This applies to the Standalone CA, and Subordinate CA certificates issued
by the Enterprise CA.

The template validity period.
This applies to the Enterprise CA. Templates supported by Windows 2000 and
Windows Server 2003 Standard Edition cannot be modified. Templates
supported by Windows Server Enterprise Edition (Version 2 templates) do
support modification."

Hope this helps,

Brian Delaney
Microsoft Canada
--

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
Thread-Topic: CA Client Certificates only expire in one years time
thread-index: Acdww6tW8PJSsF7lRyyuI1Yc8PWpCA==
X-WBNR-Posting-Host: 203.97.107.160
From: =?Utf-8?B?Um9tYW4=?= <Roman@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: CA Client Certificates only expire in one years time
Date: Tue, 27 Mar 2007 16:00:09 -0700

Hi there,

I've got a windows 2003 Standard Edition server that I've just added the
MS
Certification Authorirty to. I've set up the CA to expire in five years
time
- March 2012. The problem I've got is that when I try to generate and
install the certificates on the client machines it installs them fine but
the
client-certificates expire in March 2008 - only one year away!

I'd like these certificates to expire in two years time. I've been
looking
for similar issues on the Net and keep coming across this article:
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q254632

The thing is that my default settings are actually two years:
ValidityPeriod is Years
ValidityPeriodunits is 2

I've changed these values to time periods of less than one year and
restarted the cert service and it works fine. I then tried changing these
values to 3 years and also tried 24 months but in both cases it sets the
expiry period on the generated client certs to March 2008.

Does anyone know why this is setting the client certificates to a maximum
on
one year?

Any help would be most appreciated.


.



Relevant Pages

  • RE: CA Client Certificates only expire in one years time
    ... If this was installed as an Enterprise CA this is normal. ... which in v1 templates cannot be modified. ... "For certificates that are issued by Enterprise CAs, the validity period is ...
    (microsoft.public.windows.server.general)
  • Re: Adding the Certificate Templates to the Certification Authority
    ... version 2 templates are only available from a W2003 Enterprise CA. ... though MS does have 802.1X download for Windows 2000. ... to use PEAP which does not require certificates on the clients. ...
    (microsoft.public.security)
  • Re: RPC Server Unavailable When Requesting Computer Certificate
    ... The biggest issue you face is that you can only issue certificates based ... on version 1 templates in your configuration. ... on standard edition cannot issue certificates based on version 2 ... Why I am harping on this is that if the CA was running on enterprise ...
    (microsoft.public.windows.server.security)
  • Re: RPC Server Unavailable When Requesting Computer Certificate
    ... The biggest issue you face is that you can only issue certificates based ... on version 1 templates in your configuration. ... on standard edition cannot issue certificates based on version 2 ... Why I am harping on this is that if the CA was running on enterprise ...
    (microsoft.public.security)
  • Re: 2003/R2 certificate server questions
    ... running OPenSSL to service requests from Linux/samba ... certificates, but I also want to be able to issue random certificates ... Make sure you are running on Enterprise Edition, ... Automatic certs, Key archival and recovery, customizable ...
    (microsoft.public.windows.server.security)