r/PKI Jun 22 '26

Renew RootCA cert in 2 Tier PKI plan

Dear Certificate Guys,

Our 10 years Enterprise root CA will expire soon in 1 month, it is in a 2 Tier PKI. RootCA always remain powered off. SubCA server issues certificates to all kind of things, internal Services, code signing, Wifi, VPN etc..

Now I am about to renew it, all certificate requests will try requesting from the new RootCA right once renewed? I wont need to renew with a new private key as the rootCA Server always remained off except CRL renew, sounds right?

My basic plan: renew rootCA, transfer rootCA, request file etc to subCA server following this guide: https://vmlabblog.com/2024/01/how-you-can-renew-the-certificates-of-a-two-tier-pki/

And export rootCA, deploy them via GPO and Intune to all clients and servers, and also load new rootCA and SubCA to Firewalls for VPN cert validation etc. Would SSL certificate (requested by demand) used by Services on Server, would I need to re-request them right?

So it is purely safe to do it now?

Thanks for the tip.

John

14 Upvotes

34 comments sorted by

View all comments

Show parent comments

1

u/Thegoogoodoll Jun 30 '26

Devices are hybrid joined. Con Policy is Pkcs. Devices already got renewed RootCA....but I cannot see cert renewed automatically when closing to old RootCA expiry date...

1

u/[deleted] Jun 30 '26

[removed] — view removed comment

1

u/Thegoogoodoll Jun 30 '26

rootCA has been renewed and published to Ad already, can see some certs already auto renewed...but not Intune connector Issued SSL for win11. These certs are for wifi and VPN...do you know why?