Skip to content
Discussion options

You must be logged in to vote

CA renewal with re-key and CRLs is a tricky topic. Because of that the most common practice is to create a new CA instead of re-key an existing CA. That's why public Cas typically have "G2" (generation), "G3", etc. Avoids that complexity.

The default behavior of EJBCA is to only generate CRLs using the current CA signing key. If end entities does not have the new CA key, they can not verify that CRL naturally.
See "Microsoft CA compatibility mode" for information how to create multiple CRLs with current and old keys.
https://doc.primekey.com/ejbca/ejbca-operations/ejbca-ca-concept-guide/certificate-authority-overview/microsoft-compatible-ca-key-updates

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@Sidxzx
Comment options

Answer selected by Sidxzx
Comment options

You must be logged in to vote
1 reply
@Sidxzx
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants