![]() ![]() When this command is run the Certificate Service Service on the subordinate CA will start. Using the following command: CertUtil -InstallCert CACertFileNameĮxample: Certutil -InstallCert FourthCoffeeSubCACert.cer Back on the subordinate CA in an elevated command prompt we then need to install the subordinate CA's certificate. Assuming the Root CA's certificate has not been renewed, we just need to copy the resultant FourthCoffeeSubCACert.cer file back to the subordinate CA that is being renewed.Ĩ. We next need to retrieve the CER/CRT file from the Root CA so that we can install the certificate on the Subordinate CA to complete the renewal.ĬertUtil -View -Restrict "RequestID= RequestIDNumber" -out RawCertificate > C:\FourthCoffeeSubCACert.cerħ. However, since the Root is also running the Windows Core OS, we must run the following command:Įxample of the command line: Request ID from step 4: Request ID = 3ĬertUtil -Config "\FourthCoffee Root CA 01" -resubmit 3Ħ. If the CA Manager needs to approve the CSR, this can be accomplished via the certificate services management UI (cetsrv.msc) if possible as it is easier. You will need to make a note of this for forthcoming steps.ĥ. IMPORTANT: You should get a Request ID as part of the output. Sub CA CSR File Name: FourthCoffeeSubCARenewal01.reqĬertReq -Submit -Config "\FourthCoffee Root CA 01" FourthCoffeeSubCARenewal01.req We are going to use the Certreq.exe command to submit this request to the Standalone Root CA.ĬertReq -Submit -Config " RootCAComputerDNSName\ RootCAName" SubCACSRFIleName.req ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |