My self-generated CA is nearing it's end-of-life; what are the best practices for CA-rollover?

Posted by Alphager on Pro Webmasters See other posts from Pro Webmasters or by Alphager
Published on 2011-01-02T13:28:00Z Indexed on 2011/01/02 13:58 UTC
Read the original article Hit count: 218

Filed under:
|
|

Some buddies and me banded together to rent a small server to use for email, web-hosting and jabber. Early on we decided to generate our own Certificate Authority(CA) and sign all our certificates with that CA. It worked great! However, the original CA-cert is nearing it's end-of-life (it expires in five months). Obviously, we will have to generate a new cert and install it on all our computers. Are there any best practices we should follow? We have to re-generate all certs and sign them with the new CA, right?

© Pro Webmasters or respective owner

Related posts about security

Related posts about ssl