12-05-2021 10:47 PM
Hi all,
We need to renew internal root certificate. When i try to import the new root certificate, it gives an alert
“A certificate with the the same private key has already been imported. In some situations, it may be necessary to import a duplicate certificate in ISE, for example, when a certificate is renewed in Microsoft CA Services without replacing the private key. If you proceed, the existing certificate will be replaced. Do you wish to replace the existing certificate?”.
If it replaces the old root certificate with the new one, do we need to renew the certificates that installed on the nodes used for EAP, admin, portal etc. ?
Thanks,
12-06-2021 02:25 PM
If you renewed the CA certificate without changing the private key, the certificates signed by the previous CA will still trust the new Root CA cert. The serial number of the Root cert will change, but if you look at the identity certificates, they should still show that 'Certificate status is good'.
12-07-2021 10:36 PM
Hi Greg,
Thanks for your response. The MS Teams stated that the private key is not changed. The only change is the encryption type. It is changed from sha1 to sha256. Is this become a problem ?
Thanks,
12-08-2021 01:56 PM
As long as the private key has not changed, it should not affect the certificate trust. However, if your identity certificates are also using SHA1, you should also replace them with new SHA256 certificates to increase the level of security.
10-22-2024 11:24 AM - edited 10-22-2024 11:25 AM
How did it go?
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide