Deleted Root CA offline! 2 Tier Heirarchy

Terra 0 Reputation points
2023-12-22T15:50:24.25+00:00

Offline Root CA server has been deleted and it has almost been a month!! Root CA certificate will expire 2036, AIA location #1 will expire on 2036 and CDP location will expire on 2026. What are the things I must do to check that certificates are still working and will have an ample time to rebuilt the PKI infra (IF this is the last option) ?

We have 2 tier hierarchy and as far I can tell the issuing CA is still issuing certificate and revoking.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 36,266 Reputation points Moderator
    2023-12-22T16:39:29.87+00:00

    Hi @Terra

    When the CA root server is offline , you should renew the CDP manually when it wiil be expired.

    It's recommended to keep CA root offline but not deleted it. You will need restart it when the root certificate or CDP expire to renew them.

    Don't forget to backup the CA root server to be able to restore it if it is deleted by mistake.


    Please don't forget to accept helpful answer


  2. Anonymous
    2023-12-25T06:08:53.8466667+00:00

    Hello Terra,
    Thank you for posting in Q&A forum.

    Based on the description above, I understand you have two-tier PKI, one offline standalone root CA server and one online enterprise issuing CA server.

    Based on "Offline Root CA server has been deleted", how did you delete Offline Root CA server? Did you mean you delete root CA certificate or root CA server?

    If you still need the two-tier PKI, you cannot delete the root CA server or delete root CA certificate.

    If you have already deleted the root CA server and you have the back up of the root CA, you can try to rebuild one server and install offline standalone root CA server and restore it.

    I hope the information above is helpful.

    If you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.