Skip to content
Discussion options

You must be logged in to vote

For Root CAs, while technically you can simply renew the existing Root CA using the same CA subject DN (with a button in EJBCA), the best practice today is to create a new Root CA with a difference subject DN. Setting up a new Root with a different subject DN makes it more clear, and less error prone when you distribute the new Root CA certificate, with no risk of any client/toolkit/human out there to mess up certificate chains.

For specific use cases, there is a functionality (Service) in EJBCA for automatic CA renewal, which is typically used for short lived Sub CAs though where the whole process can be automated, and not for Root CAs.

While technically the standards allow for many many…

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@syamimirfan
Comment options

@primetomas
Comment options

@syamimirfan
Comment options

Answer selected by primetomas
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants