# Expired CA root with valid sub CA

**URL:** https://community.ciphermail.com/t/expired-ca-root-with-valid-sub-ca/156
**Category:** Gateway
**Created:** [January 20, 2011, 10:43am UTC](https://community.ciphermail.com/t/expired-ca-root-with-valid-sub-ca/156 "2011-01-20T10:43:00Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)
#### Post date: [January 20, 2011, 10:43am UTC](https://community.ciphermail.com/t/expired-ca-root-with-valid-sub-ca/156/1 "2011-01-20T10:43:00Z")

</div>

Hello

we have a problem with certificates used by some customers which are  
basically valid (certificate and sub CA) but have expired root-CA. We  
have deleted the expired root-CA some time ago and now all user  
certificates are invalid.  
Is it even PKI conform to have sub-CA and certificates with longer  
validity than the root-CA?

The problem CA is from  
[https://www.trustcenter.de/infocenter/root\_certificates.htm#1432](https://www.trustcenter.de/infocenter/root_certificates.htm#1432)

The sub-CA is for example  
[https://www.trustcenter.de/infocenter/root\_certificates.htm#2031](https://www.trustcenter.de/infocenter/root_certificates.htm#2031)

Many Thanks

Andreas

---

<div class="post-metadata">

### Author: ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)
#### Post date: [January 20, 2011, 10:56am UTC](https://community.ciphermail.com/t/expired-ca-root-with-valid-sub-ca/156/2 "2011-01-20T10:56:59Z")

</div>

> Is it even PKI conform to have sub-CA and certificates with longer  
> validity than the root-CA?

Although it's a bit strange to give the sub-CA a longer validity period  
than the root, it's PKI not problematic because the certificates are  
only valid if the complete chain is valid. What sometimes happens is  
that CAs reuse the private key from the root (or sub-CA) to issue a new  
CA certificate with a new validity period. It could be that they have  
issued a new root with the same key.

> we have a problem with certificates used by some customers which are  
> basically valid (certificate and sub CA) but have expired root-CA. We  
> have deleted the expired root-CA some time ago and now all user  
> certificates are invalid.

Do you still want to continue using those certificates to encrypt with?  
are are you going to use new certificates?

If you want to keep using those certificates if when the root is missing  
or expired you can force them to be 'valid' for encryption by adding the  
individual certificates to the "Certificate Trust List" (white list the  
certificates). You should do this only if you are certain that the  
certificates are valid for the recipient.

Kind regards,

Martijn

> **···**
>
> --  
> Djigzo open source email encryption

---

<div class="post-metadata">

### Author: ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)
#### Post date: [January 20, 2011, 11:33am UTC](https://community.ciphermail.com/t/expired-ca-root-with-valid-sub-ca/156/3 "2011-01-20T11:33:14Z")

</div>

Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:

> > Is it even PKI conform to have sub-CA and certificates with longer  
> > validity than the root-CA?
> 
> Although it's a bit strange to give the sub-CA a longer validity period  
> than the root, it's PKI not problematic because the certificates are  
> only valid if the complete chain is valid. What sometimes happens is  
> that CAs reuse the private key from the root (or sub-CA) to issue a new  
> CA certificate with a new validity period. It could be that they have  
> issued a new root with the same key.

So in fact the certificates issued by trustcenter.de are invalid  
because the root-CA is invalid (expired)?

The chain is as follow:

root-CA : valid from 09.03.1998 11:59:59 GMT - 01.01.2011 11:59:59 GMT  
--\> expired

sub-CA : Nov 26 16:01:23 2007 GMT - Dec 31 22:59:59 2025 GMT

certificate : 23.03.2008 until 23.03.2011

> > we have a problem with certificates used by some customers which are  
> > basically valid (certificate and sub CA) but have expired root-CA. We  
> > have deleted the expired root-CA some time ago and now all user  
> > certificates are invalid.
> 
> Do you still want to continue using those certificates to encrypt with?  
> are are you going to use new certificates?
> 
> If you want to keep using those certificates if when the root is missing  
> or expired you can force them to be 'valid' for encryption by adding the  
> individual certificates to the "Certificate Trust List" (white list the  
> certificates). You should do this only if you are certain that the  
> certificates are valid for the recipient.

This is a little bit awkward because the certificates are used by  
external users. So from time to time a certificate is greeped by  
Djigzo but can't be used because of expired root-CA. The certificates  
from www.trustcenter.de are commonly used in germany and with a 3 year  
validity we expect to see some more of the signed by the old root. I  
even wonder if Trustcenter.de have noticed the problem because they  
still seem to issue certificates signed by the sub-CA which belong to  
the expired root-CA.

Many Thanks

Andreas

---

<div class="post-metadata">

### Author: ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)
#### Post date: [January 20, 2011, 12:18pm UTC](https://community.ciphermail.com/t/expired-ca-root-with-valid-sub-ca/156/4 "2011-01-20T12:18:49Z")

</div>

> So in fact the certificates issued by trustcenter.de are invalid because  
> the root-CA is invalid (expired)?
> 
> The chain is as follow:
> 
> root-CA : valid from 09.03.1998 11:59:59 GMT - 01.01.2011 11:59:59 GMT  
> --\> expired
> 
> sub-CA : Nov 26 16:01:23 2007 GMT - Dec 31 22:59:59 2025 GMT
> 
> certificate : 23.03.2008 until 23.03.2011

It seems that they have issued a new root certificate. It looks like  
they have introduced a cross certificate into the chain to make the  
'old' non expired sub-ca valid.

So, you should import "Neue Root-Zertifikate/TC TrustCenter Class 2 CA  
II" with SHA1 thumbprint:

ae:50:83:ed:7c:f4:5c:bc:8f:61:c6:21:fe:68:5d:79:42:21:15:6e

and "Zwischenzertifikat / Crosszertifikat": TC TrustCenter Cross Class 2  
with SHA1 thumbprint:

51:ee:c2:46:09:78:95:9b:ae:56:ca:0a:71:eb:35:d6:ca:04:21:2d

The sub-ca that was used to sign the certificates is now trusted again.

I think that they introduced the cross certificate as a way to start  
using the new root.

Kind regards,

Martijn

> **···**
>
> --  
> Djigzo open source email encryption

---

<div class="post-metadata">

### Author: ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)
#### Post date: [January 20, 2011, 12:45pm UTC](https://community.ciphermail.com/t/expired-ca-root-with-valid-sub-ca/156/5 "2011-01-20T12:45:58Z")

</div>

Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:

> > So in fact the certificates issued by trustcenter.de are invalid because  
> > the root-CA is invalid (expired)?
> > 
> > The chain is as follow:
> > 
> > root-CA : valid from 09.03.1998 11:59:59 GMT - 01.01.2011 11:59:59 GMT  
> > --\> expired
> > 
> > sub-CA : Nov 26 16:01:23 2007 GMT - Dec 31 22:59:59 2025 GMT
> > 
> > certificate : 23.03.2008 until 23.03.2011
> 
> It seems that they have issued a new root certificate. It looks like  
> they have introduced a cross certificate into the chain to make the  
> 'old' non expired sub-ca valid.
> 
> So, you should import "Neue Root-Zertifikate/TC TrustCenter Class 2 CA  
> II" with SHA1 thumbprint:
> 
> ae:50:83:ed:7c:f4:5c:bc:8f:61:c6:21:fe:68:5d:79:42:21:15:6e
> 
> and "Zwischenzertifikat / Crosszertifikat": TC TrustCenter Cross Class 2  
> with SHA1 thumbprint:
> 
> 51:ee:c2:46:09:78:95:9b:ae:56:ca:0a:71:eb:35:d6:ca:04:21:2d
> 
> The sub-ca that was used to sign the certificates is now trusted again.
> 
> I think that they introduced the cross certificate as a way to start  
> using the new root.

Thanks, i have tottaly overlooked the cross-certs. IMHO cross  
certification is evil as hell anyway and can lead to a total mess in  
the trust chain.  
But nothing Djigzo is responsible for as always. With the import of  
the cross-certs its now working with the new root-CA.

Regards

Andreas
