Digi-Sign, The Certificate Corporation
Published on Digi-Sign, The Certificate Corporation (https://www.digi-sign.com)

Home > Replacing an Existing CA

By Digi-Sign
Created Feb 22 2008 - 16:32

Replacing an Existing CA

PDF [1] If you are trying to migrate [2] an existing environment from another Traditional Certificate Authority [3] [CA] vendor to Digi-CA™ [4], there is a ready-to-go solution that works independently from the Traditional CA. The customer can provide the information manually or the Digi-CA Assistant™ can help minimize the migration process by using unobtrusive network scanning.

This is how it works:

  • A list of all existing Certificates is provided, including all of the following information:

        • Certificate Subject Details
        • Expiry Date
        • Certificate with Public Key
        • Certificate Issuer: Signer CA Certificate with Public Key


  • The information provided by the customer is loaded into the Digi-CA™ [4] system using the Digi-CA™ Control Centre;

  • Based on the information provided, the Digi-CA™ will send expiry reminder emails according to the expiry reminder policy and each email will contain a unique URL for the Certificate renewal;

  • For client certificate [5] migration, once the user enters the Certificate renewal screen using the URL provided in the email, they will be prompted by the system to prove their identity using their existing (old) Client Certificate (this is achieved by Digi-Access™ [6] using the Client Certificate Authentication [7] method over a Secure Socket Layer [SSL] [8] or Transport Layer Security [TLS] connection) and only if the old user Certificate details match the pre-configured Digi-CA™ system data, will the user be allowed to renew their certificate.

  • For SSL Certificates, the Digi-CA™ is preconfigured in the same way as for Client Certificates except that it doesn’t require the old Certificates details other than the expiry date so that the replacement occurs seamlessly. To automate the entire life cycle of your SSL environment, see the Automated & Authenticated Certificate Delivery™ System [9].

  • This is the highly effective method used to replace older and more costly Traditional CA systems. If needed, the Digi-CAST1™ Team of professional advisors outlined in sub section 2.4.1.1 will assist you in every detail.


Understanding Online Security

    If you want to use the Internet as a tool to improve communications, reduce costs, to improve customer service and retention or to expand your market reach, then Digi-Sign’s products, services and solutions will help you.

    These same offerings can be used in physical border control, building access, electronic signatures and any situation where truly knowing the other person/device is a necessity to securing the transaction.


  • Migration

Source URL: https://www.digi-sign.com/digital%20certificate/migrating%20certificate%20authority

Links:
[1] https://www.digi-sign.com/downloads/download.php?id=digi-ca-pdf
[2] https://www.digi-sign.com/digi-ca/migration
[3] https://www.digi-sign.com/certificate+authority/traditional+ca
[4] https://www.digi-sign.com/digi-ca
[5] https://www.digi-sign.com/digital+certificate
[6] https://www.digi-sign.com/digi-access
[7] https://www.digi-sign.com/two+factor+authentication
[8] https://www.digi-sign.com/ssl+certificate
[9] https://www.digi-sign.com/aacd