Should a certificate be revoked before renew or reissue
-
Hello everyone,
I was going to renew a certificate and the following message appears at the top of the Renew or Reissue page:
Renewing or reissuing a CA or certificate will replace the old entry. The old entry will be lost, and cannot be revoked after it has been replaced. Daemons known to be using this entry or one of its descendents will be restarted after the entry is replaced.Should a certificate be revoked before it is renewed or reissued?
Thanks for any advice.
-
@john-l said in Should a certificate be revoked before renew or reissue:
Should a certificate be revoked before it is renewed or reissued?
No.
'revoking' comes into play when you know some one 'stole' your private certificate files.Most often, the old files will get deleted or overwritten. They will expire anyway.
-
The answer is "it depends".
Renewing a certificate because the old one is about to expire? Then it's not worth revoking.
Renewing a certificate because you increased its security (e.g. reducing the lifetime of a server cert), then perhaps it's a good idea.
Reissuing a certificate because the user lost their laptop or phone that had the certificate on there? Definitely revoke it.
Also just because you can't revoke the old one by clicking it in the GUI doesn't mean it can't be revoked entirely. If you keep a record of the old certificate serial number you can always revoke using that serial at a later time.
-
Thanks for your answers, very informative.