Answered by:
Convert an Enterprise Root CA to an Offline Root CA

Question
-
Hello,
One of our clients has a single enterprise root CA and they now want to implement a CA hierarchy with an offline root CA. Is there a way I can install an offline root CA, a new enterprise sub CA using the same keys as those of the current enterprise root CA, establish trust between the offline root and the new enterprise sub without effecting currently issued certificates?
If that doesn't work, is there any way I can do that without revoking or invalidating active certificates? Or would the only way be to scrap everything and start from scratch, causing interruption of some services for sometime until the whole work is done and new certificates can be issued?
Thank you in advance for you answer,Arie
Tuesday, February 24, 2009 2:19 PM
Answers
-
Hi,
Yes, it is possible to migrate from an Enterprise to a Stand-alone CA. Please remember that previously issued certificates may have AIA extensions that point to the issuing CA certificate. These AIA URLs need to continue to be valid.
You may also refer to the following articles:
How to move a certification authority to another server
http://support.microsoft.com/kb/298138
Migrating from a Stand-alone to an Enterprise CA
- Marked as answer by Joson Zhou Tuesday, March 3, 2009 2:19 AM
Friday, February 27, 2009 9:35 AM
All replies
-
AFAIK you cannot move an existing root CA to offline root CA
all that yo uneed to do is
create a new root CA as offline standalone root and then publish its certs and CRL
sainath Windows Driver DevelopmentWednesday, February 25, 2009 2:38 PM -
Hello Sainath,
Thank you for replying to my question.
However, I found this link and they claim it is possible. Can you please review and approve or disapprove?
http://isingh.spaces.live.com/blog/cns!D4B487C69B1A780!189.entry?ccr=2225#comment
Thanks again,
ArieWednesday, February 25, 2009 6:15 PM -
Hi,
Yes, it is possible to migrate from an Enterprise to a Stand-alone CA. Please remember that previously issued certificates may have AIA extensions that point to the issuing CA certificate. These AIA URLs need to continue to be valid.
You may also refer to the following articles:
How to move a certification authority to another server
http://support.microsoft.com/kb/298138
Migrating from a Stand-alone to an Enterprise CA
- Marked as answer by Joson Zhou Tuesday, March 3, 2009 2:19 AM
Friday, February 27, 2009 9:35 AM