Renewing an Expired Entrust CA Certificate
This section briefly describes the renewal process for expired Entrust CA certificates, and it provides a procedure that renews (or reconfigures) existing Entrust CA certificates that have expired.
Refer to the Entrust Authority technical documentation for specific details about revoking certificates, issuing new certificates, or issuing new credentials for ActivID CMS.
This documentation is not intended to be a replacement for the product-based technical documentation from Entrust Authority. For specific information related to updating or enabling an Entrust certificate that has expired or for using the Entrust Authority software, refer to the Entrust Authority Operator Guide or other documents in the Entrust Authority suite of technical documentation.
When an Entrust Authority certificate expires, becomes disabled or invalid, the following actions must be taken:
-
Revoke the Entrust subordinate CA certificate (this requires using the Entrust Authority Administrative console).
-
Issue a new Entrust CA certificate (this requires using the Entrust Authority Administrative console).
-
Issue new credentials for ActivID CMS (this requires using an existing Entrust profile, soft token or HSM, and using the Entrust Authority Administrative console).
-
Update the Entrust CA configuration in ActivID CMS (this requires using the ActivID CMS Operator Portal; for more details, refer to Procedures for Configuring Connections to Certificate Authorities).
-
Renew all Entrust certificates for use (updating the cards to reflect the Entrust Authority certificate that was renewed).
For information on replacing the ActivID CMS server certificate on Windows platforms using Microsoft IIS servers, refer to Installing ActivID CMS for details and procedures.
-
On the Operator Portal, click the Configuration tab.
-
Click Repositories. The Repositories Management page appears.
-
Select the existing Entrust CA that you intend to renew. The Certificate Authority Creation page appears:
-
Provider—Select Entrust Authority (X509, ESP).
-
Template—Select Entrust Authority X509.
-
Click Submit. The Certificate Authority Creation page appears:
-
Name—Enter the name that identifies the CA within ActivID CMS that you want to renew.
-
Entrust configuration file—Enter the full name (including the full path) of the entrust.ini file on the ActivID CMS server.
-
Entrust profile—Enter the full name (including the full path) of the Administrator .epf file on the ActivID CMS server. (If you are using an RA credential in the HSM, this would be a .tkn file instead of the .epf file.)
-
Password—Enter the password associated with the .epf file. (If you are using an RA credential in the HSM, enter the HSM PIN which acts as the token password.)
-
For HSM-based credentials, specify the Slot ID; otherwise, specify 0 —Enter the ID number of the HSM slot used for the Entrust credential (only used if the Entrust profile configured is a .tkn file; i.e., if the RA credential is in the HSM).
If the Entrust profile is configured as a .epf file (case of an RA credential not in an HSM), this value must be set to 0. -
Activation code lifetime (seconds)—Enter the activation code lifetime duration in seconds (the recommended value is 600).
-
Security Manager connections—Enter the maximum number of concurrent connections that the Credential Provider opens to the Entrust Authority Security Manager (the range is from 1 through 50, with the recommended value being 50).
Note: The more connections you open to the Credential Provider, the faster ActivID CMS can issue additional cards concurrently. -
Connection refresh interval (minutes)—Enter the number of minutes for a connection refresh interval, after which a connection is routinely refreshed (the range is from 1 through 1440, with the recommended value being 120).
-
Connection attempts—Enter the number of times that a context thread can attempt to gain a security manager connection before it is considered to have failed and this status is reported (the recommended value is 3).
-
Default Security Manager key size—Select the default key size (in bits) for certificates in the Entrust Authority Security Manager.
Note: The value you enter must match the default key size that is configured in the Entrust Authority Security Manager. -
Click Test to verify that you can connect to the CA.
-
Click Create. A confirmation message appears.
-
Click Done.
In the Certificates Authorities panel of the Repositories Management page, you will see the Entrust Authority X509 certificate is present:
-
In the Action column next to the Entrust Authority X509 certificate, click Update to update the ActivID CMS server with this certificate.