Renewing/Replacing the Signing Certificate

Last Updated : Apr 19, 2022 |
Prolog information

To create a new signing certificate:

  1. Select Platform ViewSettingsGeneralCertificatesCA CertificateCreate New.
  2. This will create a completely new root CA certificate and will also require new ID certificates for all entities. The previous signing certificate will be deleted.

To keep all existing ID certificates but refresh the signing certificate:

Care must be taken not to abuse the convenience of this feature as the longer the public/private keys are unchanged, the greater the risk of compromise.
  1. Select Platform ViewSettingsGeneralCertificatesCA CertificateRenew Existing.
  2. This will create a new certificate with the same content and public/private keys, but a different serial number and start/end date.
  3. Only this new root CA requires distribution, in-date existing ID certificates signed by the previous CA will still be valid.

To replace the existing signing certificate:

  1. Select Platform ViewSettingsGeneralCertificatesCA CertificateImport.
  2. The format must be PKCS#12.
  3. This will replace the signing certificate and may require new ID certificates for all entities

To back-up the signing certificate:

  1. Select Platform ViewSettingsGeneralCertificatesCA CertificateExport.
  2. A password is requested to secure the PKCS#12 file
  3. A popup will prompt to save the file which is named 'root-ca-p12'. Save the file to the local machine and add a '.p12' extension.

To restore the signing certificate:

  1. Select Platform ViewSettingsGeneralCertificatesCA CertificateImport.