Change expiration date of certificates - Windows Server (2024)

  • Article

This article describes how to change the validity period of a certificate that is issued by Certificate Authority (CA).

Original KB number: 254632

Summary

By default, the lifetime of a certificate that is issued by a Stand-alone Certificate Authority CA is one year. After one year, the certificate expires and is not trusted for use. There may be situations when you have to override the default expiration date for certificates that are issued by an intermediate or an issuing CA.

The validity period that is defined in the registry affects all certificates that are issued by Stand-alone and Enterprise CAs. For Enterprise CAs, the default registry setting is two years. For Stand-alone CAs, the default registry setting is one year. For certificates that are issued by Stand-alone CAs, the validity period is determined by the registry entry that is described later in this article. This value applies to all certificates that are issued by the CA.

For certificates that are issued by Enterprise CAs, the validity period is defined in the template that is used to create the certificate. Windows 2000 and Windows Server 2003 Standard Edition do not support modification of these templates. Windows Server 2003 Enterprise Edition supports Version 2 certificate templates that can be modified. The validity period defined in the template applies to all certificates issued by any Enterprise CA in the Active Directory forest. A certificate that is issued by a CA is valid for the minimum of the following periods of time:

  • The registry validity period that is noted earlier in this article.

    This applies to the stand-alone CA, and Subordinate CA certificates issued by the Enterprise CA.

  • The template validity period.

This applies to the Enterprise CA. Templates supported by Windows 2000 and Windows Server 2003 Standard Edition cannot be modified. Templates supported by Windows Server Enterprise Edition (Version 2 templates) do support modification.

For an Enterprise CA, the validity period of an issued certificate is set to the minimum of all the following:

  • The registry validity period of the CA (for example: ValidityPeriod == Years, ValidityPeriodUnits == 1)
  • The template validity period
  • The remaining validity period of the signing certificate of the CA
  • If the EDITF_ATTRIBUTEENDDATE bit is enabled in the policy module's EditFlags registry value, the validity period specified through the request attributes (ExpirationDate:Date or ValidityPeriod:Years\nValidityPeriodUnits:1)

Note

  • The ExpirationDate:Date syntax was not supported until Windows Server 2008.
  • For a stand-alone CA, no templates are processed. Therefore, the template validity period does not apply.

The expiration date of the CA certificate

A CA cannot issue a certificate with a longer validity period than its own CA certificate.

Note

The Request Attribute name is made up of value string pairs that accompany the request and that specify the validity period. By default, this is enabled by a registry setting on a Standalone CA only.

Change expiration date of certificates issued by CA

To change the validity period settings for a CA, follow these steps.

Important

This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, see How to back up and restore the registry in Windows.

  1. Click Start, and then click Run.

  2. In the Open box, type regedit, and then click OK.

  3. Locate, and then click the following registry key:

    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CertSvc\Configuration\<CAName>

  4. In the right pane, double-click ValidityPeriod.

  5. In the Value data box, type one of the following, and then click OK:

    • Days
    • Weeks
    • Months
    • Years
  6. In the right pane, double-click ValidityPeriodUnits.

  7. In the Value data box, type the numeric value that you want, and then click OK. For example, type 2.

  8. Stop, and then restart the Certificate Services service. To do so:

    1. Click Start, and then click Run.

    2. In the Open box, type cmd, and then click OK.

    3. At the command prompt, type the following lines. Press ENTER after each line.

      net stop certsvcnet start certsvc
    4. Type exit to quit Command Prompt.

Change expiration date of certificates - Windows Server (2024)
Top Articles
Federal Student Aid
How Long Does It Take to Make an App? | Uptech
Riverrun Rv Park Middletown Photos
#ridwork guides | fountainpenguin
Kathleen Hixson Leaked
Mcgeorge Academic Calendar
Insidious 5 Showtimes Near Cinemark Tinseltown 290 And Xd
America Cuevas Desnuda
Sissy Hypno Gif
Select The Best Reagents For The Reaction Below.
Barstool Sports Gif
AB Solutions Portal | Login
Music Archives | Hotel Grand Bach - Hotel GrandBach
Ecers-3 Cheat Sheet Free
Cooktopcove Com
Huge Boobs Images
Nyuonsite
Images of CGC-graded Comic Books Now Available Using the CGC Certification Verification Tool
Echat Fr Review Pc Retailer In Qatar Prestige Pc Providers – Alpha Marine Group
Vermont Craigs List
Cincinnati Adult Search
Optum Urgent Care - Nutley Photos
Mybiglots Net Associates
Macu Heloc Rate
California Online Traffic School
Kroger Feed Login
10 Best Places to Go and Things to Know for a Trip to the Hickory M...
Albertville Memorial Funeral Home Obituaries
*!Good Night (2024) 𝙵ull𝙼ovie Downl𝚘ad Fr𝚎e 1080𝚙, 720𝚙, 480𝚙 H𝙳 HI𝙽DI Dub𝚋ed Fil𝙼yz𝚒lla Isaidub
1475 Akron Way Forney Tx 75126
Workboy Kennel
Of An Age Showtimes Near Alamo Drafthouse Sloans Lake
Ark Unlock All Skins Command
Truckers Report Forums
42 Manufacturing jobs in Grayling
Mta Bus Forums
Elgin Il Building Department
Regis Sectional Havertys
Mydocbill.com/Mr
Registrar Lls
Citymd West 146Th Urgent Care - Nyc Photos
Blow Dry Bar Boynton Beach
877-552-2666
Turok: Dinosaur Hunter
Ronnie Mcnu*t Uncensored
Ihop Deliver
Is TinyZone TV Safe?
Tweedehands camper te koop - camper occasion kopen
Secondary Math 2 Module 3 Answers
683 Job Calls
Gameplay Clarkston
Www.card-Data.com/Comerica Prepaid Balance
Latest Posts
Article information

Author: Mrs. Angelic Larkin

Last Updated:

Views: 5904

Rating: 4.7 / 5 (67 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Mrs. Angelic Larkin

Birthday: 1992-06-28

Address: Apt. 413 8275 Mueller Overpass, South Magnolia, IA 99527-6023

Phone: +6824704719725

Job: District Real-Estate Facilitator

Hobby: Letterboxing, Vacation, Poi, Homebrewing, Mountain biking, Slacklining, Cabaret

Introduction: My name is Mrs. Angelic Larkin, I am a cute, charming, funny, determined, inexpensive, joyous, cheerful person who loves writing and wants to share my knowledge and understanding with you.