To keep all existing ID certificates but refresh the signing certificate:
Care must be taken not to abuse the convenience of this feature as the longer the public/private keys are unchanged, the greater the risk of compromise.
-
Select .
-
This will create a new certificate with the same content and public/private keys, but a different serial number and start/end date.
-
Only this new root CA requires distribution, in-date existing ID certificates signed by the previous CA will still be valid.