Certification Authority auto renewal

Sunghyun Park 61 Reputation points
2021-03-22T09:49:12.04+00:00

Hi. I have Windows Certification Authority. It is Enterprise CA. Here is my question. Can I prevent auto renewal my CA root certificate? How to set it? When will the certificate be renewed if it allows automatic renewal? Can the update period be set before expiration? Thanks.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,128 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2021-03-23T00:20:19.083+00:00

    Hi,

    Based on my understanding , you have an CA act as an Enterprise and root CA, right?
    If i misunderstand you ,please feel free to let me know.

    In the PKI environment , it is not supported to renew the root ca certificates automatically.
    You don' t need to do anything.
    https://social.technet.microsoft.com/Forums/lync/en-US/196a6229-c118-49e7-b073-df79e71ce5b1/auto-renew-an-enterprise-ca-root-certificate?forum=winserversecurity

    If you mean the certificates issued by CA for the clients and users , yes ,it can be set not to renew automatically.
    The certificates by the ca issued will not auto-enroll by default if the requirements didn't been meet:
    auto-enroll group policy
    auto-enroll permission for the templates
    https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-autoenrollment

    Best Regards,

    0 comments No comments