Subordinate CA Cert Validity Period Issue

Adam Weight 72 Reputation points
2022-08-19T16:21:26.423+00:00

I am trying to setup a subordinate CA in our environment to our existing root CA. The current root CA cert is valid for 22 years (issued in 2019, valid till 2041). On the subordinate CA, I want the validity of that CA cert to be 10 years, and issue certs to clients for a maximum of 5 year validity.

I have verified that the root CA validity period is set for 10 years in the registry.

232983-image.png

However, whenever I create the request for the CA cert from the subordinate and issue it from the root, it is always only for 5 years.
233012-image.png

I have tried resetting the registry entries on the root CA and restarting services, removing the sub CA role and then re-adding, but nothing seems to resolve the issue where the sub CA cert is only for 5 years. I did notice that in the root CA, there is a template for "Subordinate Certification Authority" that has a validity of 5 years, but that is a default template I cannot change. If I remove that template then the Sub CA is not issued a cert as I get the error that the root doesn't support the cert requested. If I copy that template and change the copy period to 10 years and issue that, I still get the message that the request is for an unsupported cert.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | Devices and deployment | Configure application groups
{count} votes

Accepted answer
  1. Anonymous
    2022-08-26T06:03:17.85+00:00

    Hello AdamWeight-2854,

    Thank you for posting in our Q&A forum.

    For your issue, here is a link with detailed steps about CA Validity Period Extension and CA Certificate Renewal Process (including root CA Validity Period Extension and sub CA Validity Period Extension).

    CA Validity Period Extension and CA Certificate Renewal Process
    https://www.experts-exchange.com/articles/32336/CA-Validity-Period-Extension-and-CA-Certificate-Renewal-Process.html

    Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

    I hope the information above is helpful to you.

    If anything is unclear, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.