Skip to main content
Skip table of contents

Use case in Certificate Manager: Replace old CA key

This article includes updates for CM 8.10.

This article describes how to replace an old CA key with a new CA key in Smart ID Certificate Manager, and to how to provide a new public key to all relying parties. This task is done in Administrator's workbench (AWB).

Prerequisites

-

Step-by-step instruction

Generate CA key

This is described in the article Create CA key in Certificate Manager.

Generate CA and its procedures

Follow these steps:

  1. Start the AWB application and insert the officer's smart card and log in (if not already running).

  2. In AWB, select the following objects and use Edit > Clone to make copies of the objects:

    1. CA key CA-key-<nn>

    2. CA CA-<nn>

    3. Certificate procedure Cert-<nn>

    4. CRL procedure CRL-<nn>

    5. Token procedure Token-<nn>

  3. For each cloned object, use Edit > Modify to change the name of the object from Copy of <XX-nn> to <XX-nn+1>.

  4. Click Save to finish the modifications (do not use OK).

  5. For the CA-object:

    1. Verify the validity period, starting today, ending 5 years later, in Valid from and Expiration date.

    2. Select the new Key (CA-key-<nn+1>).

    3. Change the Common Name of the CA to CA-<nn+1>.

    4. Click OK and sign the request. See Sign tasks in Certificate Manager for more information.

  6. For the certificate procedure:

    1. Select the new Issuing CA.

    2. Click OK and sign the request. See Sign tasks in Certificate Manager for more information.

  7. For the CRL procedure:

    1. Select the new CRL Issuer.

    2. Click OK and sign the request. See Sign tasks in Certificate Manager for more information.

  8. For the token procedure:

    1. For certificate procedures, delete the old certificate procedure from the list, and add the new certificate procedure.

    2. Click OK and sign the request. 

    3. See Sign tasks in Certificate Manager for more information.

Distribute CA root certificate

Follow these steps:

  1. Start the AWB application, insert the officer's smart card and log in (if not already running).

  2. In AWB, select the new CA-<nn+1> in the Authority Hierarchy.

  3. In the right-hand window, under Certificate Specification, double-click the certificate.

  4. Select the Details tab and click Copy to fileā€¦

  5. Save the DER-encoded file using the file name CA-<nn+1>.cer (where <nn+1> is the new sequence number) on a removable media.

The new CA root certificate now needs to be distributed and installed in all client and server applications using it.

Close CA and its procedures

When the key rollover is working satisfactorily, it is time to close the old CA key and the old CA procedure.

Follow these steps:

  1. Start the AWB application, insert the officer's smart card and log in (if not already running).

  2. For each one of the following objects, do the following:

    1. Select the object.

    2. Use Edit > Modify to change the State from Active to Closed.

    3. Click OK and sign the request. See Sign tasks in Certificate Manager for more information.

      These are the objects:

      • CA CA-<nn>

      • Certificate procedure Cert-<nn>

      • Token procedure Token-<nn>

The old CA key and the CRL procedures must not be closed until all certificates issued using that CA have expired.

Additional information

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.