Renewing Certificates
125
4.7.3.2. Renewing Certificates Using certutil
certutil
can be used to generate a certificate request using an existing key pair in the certificate
database. The new certificate request can then be submitted through the regular profile pages for the
CA to issue a renewed certificate.
NOTE
Encryption and signing certificates are created in a single step. However, the renewal
process only renews one certificate at a time.
To renew both certificates in a certificate pair, each one has to be renewed individually.
1. Get the password for the token database.
cat /var/lib/pki-ca/conf/password.conf
internal=263163888660
2. Open the certificate database directory of the instance that's certificate is being renewed.
cd /var/lib/pki-ca/alias
3. List the key and nickname for the certificate being renewed. In order to renew a certificate, the key
pairs used to generate and the subject name given to the new certificate must be the same as the
one in the old certificate.
# certutil -K -d .
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...