Skip to content

Self Hosted Root CA 10 year expiry renewal. #2152

Answered by tashian
ken-master asked this question in General
Discussion options

You must be logged in to vote

It can be a complex process to rotate roots.

The general steps are:

  1. Stand up a second CA and new root
  2. Add the new root to all clients as trusted
  3. Migrate all certificate issuance over to the new CA
  4. Remove old root as trusted (optional)
  5. Turn off the old CA

One thing we've added to simplify things a little, in the step client, is the contexts feature.
It lets you easily manage multiple CA connections.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by ken-master
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants