Renew a Public Key Certificate (2024)

Public key certificates have a limited lifespan. If a public key certificate has expired or is aboutto expire, it should be renewed or deleted. Renewing a public key certificatedoes not affect the key pair. It simply results in the creation of a new public key certificate with thesame public key. This new public key certificate can be signed either by the NDS* tree CA or by the same or different external CA.

A public key certificate should not be renewed if the public key size is toosmall for the desired security application or if you suspect that the private key has been compromised. Instead, the Key Material object for the service should be deleted and replaced by a new Key Material objectwith a new key pair. For liability reasons, some external CAs may prohibit therenewal of public key certificates without also renewing the key pair.

In addition, if the distinguished name or attributes of the subject change, there may be legal differences in the way a digital signature isviewed. For example, in a community property state, renewing a public keycertificate to include a woman's married name without changing the key pair could exposeher husband to liability for previously signed documents. Likewise, changingthe state or locality in a public key certificate might cause the legality of asignature to be evaluated against the laws of two different jurisdictions.

For these reasons, you should not renew a public key certificate withoutchanging the key pair.

Renew a Public Key Certificate Signed by the NDS Tree CA

1. Start NetWare* Administrator.

2. Double-click the Key Material object Renew a Public Key Certificate (1) that contains the public key certificate you want to renew.

3. Click the Public Key Certificate page.

4. Click Renew.

You are prompted to indicate whether you want to renew the public keycertificate using the Tree CA or an external CA.

5. Choose the Tree CA option.

You are prompted to indicate whether you want to create a new public keycertificate using the Standard or Custom option.

6. Choose the Standard option.

7. Click Finish.

A dialog box informs you that this change will make irreversible changes tothe Key Material object and asks you if you want to continue.

8. Choose Yes.

The Public Key Certificate page displays the distinguished name of the subjectand issuer and the validity period of the new public key certificate.

For more information about the new public key certificate, click Details.

Renew a Public Key Certificate Signed by an External CA

1. Start NetWare Administrator.

2. Double-click the Key Material object Renew a Public Key Certificate (2) that contains the public key certificate you want to renew.

3. Click the Public Key Certificate page.

4. Click Renew.

You are prompted to indicate whether you want to renew the public keycertificate using the Tree CA or an external CA.

5. Choose the External CA option.

You are prompted to indicate whether you already have the new public keycertificate from the external CA.

6. Choose No.

You are prompted to indicate whether you want to create a new public keycertificate using the Standard or Custom option.

7. Choose the Standard option.

8. Click Finish.

A dialog box informs you that this change will make irreversible changes tothe Key Material object and asks you if you want to continue.

9. Choose Yes.

A dialog box displays the certificate signing request (CSR).

10. Indicate whether you want the CSR saved to the clipboard by clicking theappropriate option. If you choose the File option, type in a filename or browse forthe file to save the CSR in.

11. Click Save.

12. Click OK.

The Public Key Certificate page displays the distinguished name of the subjectand issuer and the validity period of the previous public key certificate. This publickey certificate will remain in the Key Material object until the new public keycertificate is imported.

13. Submit the CSR to the CA.

14. When the public key certificate has been returned by the CA, obtain the CA'spublic key certificate.

15. Go to the same Key Material object and click the Trusted Root tab.

16. Click Replace.

A warning appears informing you that installing a new trusted root certificatewill delete the current public key certificate in the object.

17. Click OK.

A dialog box asks for the trusted root certificate.

18. Copy the CA's public key certificate into the clipboard and paste it into theedit box, or choose the File option and indicate the filename in which the CA'spublic key certificate was saved.

19. Click Add.

A dialog box informs you that this change will make irreversible changes tothe Key Material object and asks if you want to continue.

20. Click Yes

The Trusted Root page displays the distinguished name of the subject andissuer and the validity period of the CA's public key certificate.

21. Click the Public Key Certificate page.

22. Click Import.

23. Copy the new public key certificate into the clipboard and paste it intothe edit box, or choose the File option and indicate the filename in which thenew public key certificate was saved.

24. Click Add.

A dialog box informs you that this change will make irreversible changes tothe Key Material object and asks you if you want to continue.

25. Click Yes.

The Public Key Certificate page displays the distinguished name of the subjectand issuer and the validity period of the new public key certificate.

For more information about the new public key certificate, click Details.

Related Topics

Understanding Public Key Certificate Expiration

Renew a Public Key Certificate (2024)
Top Articles
50 budget recipes to feed a large crowd
Crypto Margin Trading: Investor’s Guide 2024 | CoinLedger
Fan Van Ari Alectra
Mountain Dew Bennington Pontoon
Mopaga Game
Summit County Juvenile Court
Gameday Red Sox
About Goodwill – Goodwill NY/NJ
Fire Rescue 1 Login
Jcpenney At Home Associate Kiosk
Craigslist Pikeville Tn
Accuradio Unblocked
Colts Snap Counts
How do I get into solitude sewers Restoring Order? - Gamers Wiki
Odfl4Us Driver Login
Lehmann's Power Equipment
V-Pay: Sicherheit, Kosten und Alternativen - BankingGeek
Craigslist Southern Oregon Coast
Caledonia - a simple love song to Scotland
Www.patientnotebook/Atic
Обзор Joxi: Что это такое? Отзывы, аналоги, сайт и инструкции | APS
Turbo Tenant Renter Login
Kabob-House-Spokane Photos
Craigslist Ludington Michigan
Arlington Museum of Art to show shining, shimmering, splendid costumes from Disney Archives
Marilyn Seipt Obituary
UAE 2023 F&B Data Insights: Restaurant Population and Traffic Data
10 Best Quotes From Venom (2018)
Courtney Roberson Rob Dyrdek
Kelley Fliehler Wikipedia
Busted! 29 New Arrests in Portsmouth, Ohio – 03/27/22 Scioto County Mugshots
Human Unitec International Inc (HMNU) Stock Price History Chart & Technical Analysis Graph - TipRanks.com
Sitting Human Silhouette Demonologist
Pickle Juiced 1234
Joe's Truck Accessories Summerville South Carolina
Are you ready for some football? Zag Alum Justin Lange Forges Career in NFL
How To Paint Dinos In Ark
Is The Nun Based On a True Story?
Lonely Wife Dating Club בקורות וחוות דעת משתמשים 2021
Walmart Car Service Near Me
Citibank Branch Locations In North Carolina
412Doctors
What Is The Optavia Diet—And How Does It Work?
Portal Pacjenta LUX MED
25 Hotels TRULY CLOSEST to Woollett Aquatics Center, Irvine, CA
Myra's Floral Princeton Wv
Houston Primary Care Byron Ga
Ics 400 Test Answers 2022
Deviantart Rwby
Primary Care in Nashville & Southern KY | Tristar Medical Group
Latest Posts
Article information

Author: Manual Maggio

Last Updated:

Views: 5876

Rating: 4.9 / 5 (69 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Manual Maggio

Birthday: 1998-01-20

Address: 359 Kelvin Stream, Lake Eldonview, MT 33517-1242

Phone: +577037762465

Job: Product Hospitality Supervisor

Hobby: Gardening, Web surfing, Video gaming, Amateur radio, Flag Football, Reading, Table tennis

Introduction: My name is Manual Maggio, I am a thankful, tender, adventurous, delightful, fantastic, proud, graceful person who loves writing and wants to share my knowledge and understanding with you.