Change expiration date of certificates - Windows Server (2024)

  • Article

This article describes how to change the validity period of a certificate that is issued by Certificate Authority (CA).

Original KB number: 254632

Summary

By default, the lifetime of a certificate that is issued by a Stand-alone Certificate Authority CA is one year. After one year, the certificate expires and is not trusted for use. There may be situations when you have to override the default expiration date for certificates that are issued by an intermediate or an issuing CA.

The validity period that is defined in the registry affects all certificates that are issued by Stand-alone and Enterprise CAs. For Enterprise CAs, the default registry setting is two years. For Stand-alone CAs, the default registry setting is one year. For certificates that are issued by Stand-alone CAs, the validity period is determined by the registry entry that is described later in this article. This value applies to all certificates that are issued by the CA.

For certificates that are issued by Enterprise CAs, the validity period is defined in the template that is used to create the certificate. Windows 2000 and Windows Server 2003 Standard Edition do not support modification of these templates. Windows Server 2003 Enterprise Edition supports Version 2 certificate templates that can be modified. The validity period defined in the template applies to all certificates issued by any Enterprise CA in the Active Directory forest. A certificate that is issued by a CA is valid for the minimum of the following periods of time:

  • The registry validity period that is noted earlier in this article.

    This applies to the stand-alone CA, and Subordinate CA certificates issued by the Enterprise CA.

  • The template validity period.

This applies to the Enterprise CA. Templates supported by Windows 2000 and Windows Server 2003 Standard Edition cannot be modified. Templates supported by Windows Server Enterprise Edition (Version 2 templates) do support modification.

For an Enterprise CA, the validity period of an issued certificate is set to the minimum of all the following:

  • The registry validity period of the CA (for example: ValidityPeriod == Years, ValidityPeriodUnits == 1)
  • The template validity period
  • The remaining validity period of the signing certificate of the CA
  • If the EDITF_ATTRIBUTEENDDATE bit is enabled in the policy module's EditFlags registry value, the validity period specified through the request attributes (ExpirationDate:Date or ValidityPeriod:Years\nValidityPeriodUnits:1)

Note

  • The ExpirationDate:Date syntax was not supported until Windows Server 2008.
  • For a stand-alone CA, no templates are processed. Therefore, the template validity period does not apply.

The expiration date of the CA certificate

A CA cannot issue a certificate with a longer validity period than its own CA certificate.

Note

The Request Attribute name is made up of value string pairs that accompany the request and that specify the validity period. By default, this is enabled by a registry setting on a Standalone CA only.

Change expiration date of certificates issued by CA

To change the validity period settings for a CA, follow these steps.

Important

This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, see How to back up and restore the registry in Windows.

  1. Click Start, and then click Run.

  2. In the Open box, type regedit, and then click OK.

  3. Locate, and then click the following registry key:

    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CertSvc\Configuration\<CAName>

  4. In the right pane, double-click ValidityPeriod.

  5. In the Value data box, type one of the following, and then click OK:

    • Days
    • Weeks
    • Months
    • Years
  6. In the right pane, double-click ValidityPeriodUnits.

  7. In the Value data box, type the numeric value that you want, and then click OK. For example, type 2.

  8. Stop, and then restart the Certificate Services service. To do so:

    1. Click Start, and then click Run.

    2. In the Open box, type cmd, and then click OK.

    3. At the command prompt, type the following lines. Press ENTER after each line.

      net stop certsvcnet start certsvc
    4. Type exit to quit Command Prompt.

Change expiration date of certificates - Windows Server (2024)
Top Articles
How to Delete Trust Wallet Account? (EASILY) | Adaas Capital
Binance Business Model and Revenue Sources Explained
Xre-02022
Lowe's Garden Fence Roll
Riverrun Rv Park Middletown Photos
Unitedhealthcare Hwp
Craigslist Portales
Doublelist Paducah Ky
Obituary (Binghamton Press & Sun-Bulletin): Tully Area Historical Society
Arrests reported by Yuba County Sheriff
What's Wrong with the Chevrolet Tahoe?
Azeroth Pilot Reloaded - Addons - World of Warcraft
Dumb Money
Sams Early Hours
Dutch Bros San Angelo Tx
Willam Belli's Husband
Andhrajyothy Sunday Magazine
Www Craigslist Milwaukee Wi
Nevermore: What Doesn't Kill
Kamzz Llc
Ahrefs Koopje
Www Craigslist Com Bakersfield
Panic! At The Disco - Spotify Top Songs
Gayla Glenn Harris County Texas Update
Mail.zsthost Change Password
north jersey garage & moving sales - craigslist
Regal Amc Near Me
Restaurants In Shelby Montana
Yale College Confidential 2027
Darknet Opsec Bible 2022
Barbie Showtimes Near Lucas Cinemas Albertville
Eegees Gift Card Balance
Allegheny Clinic Primary Care North
"Pure Onyx" by xxoom from Patreon | Kemono
After Transmigrating, The Fat Wife Made A Comeback! Chapter 2209 – Chapter 2209: Love at First Sight - Novel Cool
Acuity Eye Group - La Quinta Photos
Garrison Blacksmith's Bench
Lake Dunson Robertson Funeral Home Lagrange Georgia Obituary
Senior Houses For Sale Near Me
USB C 3HDMI Dock UCN3278 (12 in 1)
Craiglist Hollywood
Miracle Shoes Ff6
Shuaiby Kill Twitter
How Many Dogs Can You Have in Idaho | GetJerry.com
Davis Fire Friday live updates: Community meeting set for 7 p.m. with Lombardo
Jetblue 1919
Bustednewspaper.com Rockbridge County Va
Blue Beetle Showtimes Near Regal Evergreen Parkway & Rpx
Mynord
Wisconsin Volleyball titt*es
ESPN's New Standalone Streaming Service Will Be Available Through Disney+ In 2025
The Ultimate Guide To 5 Movierulz. Com: Exploring The World Of Online Movies
Latest Posts
Article information

Author: Mrs. Angelic Larkin

Last Updated:

Views: 5904

Rating: 4.7 / 5 (67 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Mrs. Angelic Larkin

Birthday: 1992-06-28

Address: Apt. 413 8275 Mueller Overpass, South Magnolia, IA 99527-6023

Phone: +6824704719725

Job: District Real-Estate Facilitator

Hobby: Letterboxing, Vacation, Poi, Homebrewing, Mountain biking, Slacklining, Cabaret

Introduction: My name is Mrs. Angelic Larkin, I am a cute, charming, funny, determined, inexpensive, joyous, cheerful person who loves writing and wants to share my knowledge and understanding with you.