Somewhat tangential, but what happens to all active certificates when the root key expires?
Somewhat tangential, but what happens to all active certificates when the root key expires?
They expire, but normally the CA wouldn't issue certificates outliving their root.
It can be a concern for legacy devices whose trust store doesn't get updated, but really no more so than any other cert expiration or revocation.
Thus, by the time the root cert expires, all client certs will already be expired.
The root CA from namecheap was expiring. They tried to recreate it, only changing the date, to continue to issue certificates to customers with it the same way.
They hoped users/systems would accept their newer CA automatically after the old CA expired. CA are additive, there are many configured on a system, it's standard practice to add more by keeping existing ones and adding new ones.
This blew up in their face monumentally because having two identical CA is conflicting. Things failed to verify after the original CA expired.