The information in this article applies to:
SYMPTOMS
A Windows 2000 server functioning as the Certificate Authority (CA) server cannot be renamed, or the certificates that it has granted become invalid. This includes both Enterprise CAs and stand-alone CAs.
CAUSEThe name of the CA server is bound to the certificates that the CA has issued. Therefore, the server name cannot be changed without revoking all certificates. RESOLUTION
Before implementing a CA server, plan factors such as organization naming schemes and future requirements for subordinate CAs so the CA hierarchy can be a part of the naming scheme. STATUSThis behavior is by design. MORE INFORMATIONLocal CA servers hold their information locally, use local policies, and store certificate information in a local database. Therefore, the CA is more than just having a server of the same name on the network for Certificate Authority. Performing regular tape backups of the server is a reliable way of being able to restore the CA without losing all certificates. Additional query words: Digital Signatures Authority
Keywords : kbenv |
Last Reviewed: December 29, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |