Server certificate for DC - can I have more than one ?

J

Jason

Hi , I need to run secure LDAPS on a DC. The certificate ( request ) is
generated using the IIS on the DC and server certificate was granted by a
standalone CA.

My questions are :

1) My experience is that after installed a certificate I have to re-boot the
server ( win 2K ) before the certificate could "take effect" , is this
correct and why ? Example , I have delete a certificate and installed with
a new one ( before it is expired ), but when users connected to it , they
said they could connect and the certificate is the same old one ?

2) Can I have more than one certificate for the same server which have the
same "CN" name , both of them enabled with "All purpose" but with a
different expiration date ? ( Or it has to be a different CN name ? E.g
WWW.servername.domain.com and servername.domain.com)

Any explanation highly appreciated.

Jason
 
B

Brian Desmond [MVP]

Jason,

My experience with #1 is that you can put a certificate in whiel the server
is up.

Not sure about #2, though I don't see why not.

--
--Brian Desmond
Windows Server MVP
(e-mail address removed)12.il.us

www.briandesmond.com
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top