-
Hi, thanks for help me with that. |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments
-
Have you tried right clicking the Root CA in the Certificates tab, and selecting "Renewal"? I've not done it myself but I expect you'd also want to check "Keep serial number" in the menu that comes up. |
Beta Was this translation helpful? Give feedback.
-
You cannot extend a CA, or any certificate for that matter. By changing it's parameters (duration of validity), it is not the same certificate anymore and so cannot be extended. So, just create a CA root certificate with the same key. BUT, the validation procedure looks for a Root CA with either the same Subject that is called the Issuer of the issued certificate, or it checks whether the Authority Key Identifier of the issued certificate matches the Subject Key Identifier of the Issuer/Root CA. To sum up, create a new certificate using the same public key and keep all the fields (well, tbh, mostly those I mentione above). FOR CONFORMANCE, make sure that, in the new certificate, you set the NotBefore/Valid from to be the SAME VALUE as the one that was set on the old certificate. Don't put the as NotBefore/Valid from the date you actually generated the new CA certificate. Doing that, will make all previously issued certificates inconformant, since they have been isues before their signing CA was generated. |
Beta Was this translation helpful? Give feedback.
-
That's actually the point of the "renewal" option and it does exactly what you described. The last paragraph is not correct. It is only necessary that all certificates in the chain are valid at the time of verification. |
Beta Was this translation helpful? Give feedback.
That's actually the point of the "renewal" option and it does exactly what you described.
The last paragraph is not correct. It is only necessary that all certificates in the chain are valid at the time of verification.
Just tried a renewed CA with different serial-number and later "valid from" date than the server certificate and Firefox did not complain.