Renewing an Expired Entrust CA Certificate
This section briefly describes the renewal process for expired Entrust CA certificates, and it provides a procedure that renews (or reconfigures) existing Entrust CA certificates that have expired.
Refer to the Entrust Authority technical documentation for specific details about revoking certificates, issuing new certificates, or issuing new credentials In the context of ActivID, a credential is a collection of one or more credential elements that together provide some form of digitally provable identity. In the context of PIV, a credential refers to the completed PIV card itself. for ActivID CMS.
This documentation is not intended to be a replacement for the product-based technical documentation from Entrust Authority. For specific information related to updating or enabling an Entrust certificate that has expired or for using the Entrust Authority software, refer to the Entrust Authority Operator Guide or other documents in the Entrust Authority suite of technical documentation.
When an Entrust Authority certificate expires, becomes disabled or invalid, the following actions must be taken:
-
Revoke the Entrust subordinate CA certificate (this requires using the Entrust Authority Administrative console).
-
Issue a new Entrust CA certificate (this requires using the Entrust Authority Administrative console).
-
Issue new credentials for ActivID CMS (this requires using an existing Entrust profile, soft token or HSM A Hardware Security Module (HSM) securely stores secret key material. They are similar to large-storage, multisession smart cards. However, unlike smart cards, they are used mainly on the server side of a system., and using the Entrust Authority Administrative console).
-
Update the Entrust CA configuration in ActivID CMS (this requires using the ActivID CMS Operator Portal; for more details, refer to Procedures for Configuring Connections to Certificate Authorities).
-
Renew all Entrust certificates for use (updating the cards to reflect the Entrust Authority certificate that was renewed).
For information on replacing the ActivID CMS server certificate on Windows platforms using Microsoft IIS servers, refer to Installing ActivID CMS for details and procedures.
-
On the Operator Portal, click the Configuration tab.
-
Click Repositories. The Repositories Management page appears.
-
Select the existing Entrust CA that you intend to renew. The Certificate Authority Creation page appears:
-
Provider—Select Entrust Authority (X509, ESP).
-
Template—Select Entrust Authority X509.
-
Click Submit. The Certificate Authority Creation page appears:
-
Name—Enter the name that identifies the CA within ActivID CMS that you want to renew.
-
Entrust configuration file—Enter the full name (including the full path) of the entrust.ini file on the ActivID CMS server.
-
Entrust profile—Enter the full name (including the full path) of the Administrator .epf file on the ActivID CMS server. (If you are using an RA A Registration Authority (RA) is an authority in a network that verifies user requests for a digital certificate and instructs the CA to issue it. An RA is part of a PKI, a networked system that enables companies and users to exchange information safely and securely. credential in the HSM, this would be a .tkn file instead of the .epf file.)
-
Password—Enter the password associated with the .epf file. (If you are using an RA credential in the HSM, enter the HSM PIN which acts as the token password.)
-
For HSM-based credentials, specify the Slot ID; otherwise, specify 0—Enter the ID number of the HSM slot used for the Entrust credential (only used if the Entrust profile configured is a .tkn file; i.e., if the RA credential is in the HSM).
If the Entrust profile is configured as a .epf file (case of an RA credential not in an HSM), this value must be set to 0. -
Activation code lifetime (seconds)—Enter the activation code lifetime duration in seconds (the recommended value is 600).
-
Security Manager connections—Enter the maximum number of concurrent connections that the Credential Provider opens to the Entrust Authority Security Manager (the range is from 1 through 50, with the recommended value being 50).
Note: The more connections you open to the Credential Provider, the faster ActivID CMS can issue additional cards concurrently. -
Connection refresh interval (minutes)—Enter the number of minutes for a connection refresh interval, after which a connection is routinely refreshed (the range is from 1 through 1440, with the recommended value being 120).
-
Connection attempts—Enter the number of times that a context thread can attempt to gain a security manager connection before it is considered to have failed and this status is reported (the recommended value is 3).
-
Default Security Manager key size—Select the default key size (in bits) for certificates in the Entrust Authority Security Manager.
Note: The value you enter must match the default key size that is configured in the Entrust Authority Security Manager. -
Click Test to verify that you can connect to the CA.
-
Click Create. A confirmation message appears.
-
Click Done.
In the Certificates Authorities panel of the Repositories Management page, you will see the Entrust Authority X509 certificate is present:
-
In the Action column next to the Entrust Authority X509 certificate, click Update to update the ActivID CMS server with this certificate.