Learn how to renew an AD CS Root CA certificate in Windows Server using the Certification Authority console, back up the CA before making changes, and publish the renewed root certificate so domain clients continue to trust it. Microsoft’s renewal guide shows the root CA renewal flow in the Certification Authority MMC, and Microsoft’s certificate distribution guidance shows how trusted roots can be deployed through Group Policy.
In this video, I walk through a practical Root CA renewal workflow: backing up the CA, renewing the CA certificate in certsrv.msc, choosing whether to reuse the existing key pair or generate a new one, exporting the renewed root certificate, and making sure clients trust the updated chain. Microsoft says renewing with a new key pair is more complex because previously issued certificates chain to the old CA certificate while newly issued certificates chain to the new CA certificate.
0:00 - Introduction
0:16 - Description
3:33 - Backup
4:15 - Replace Certificate
6:33 - Group Policy
9:03 - Conclusion
What you’ll learn:
Why Root CA expiration matters. Microsoft notes that renewal with a new key pair changes the Subject Key Identifier, which affects how older and newer certificates chain.
How to renew the Root CA in certsrv.msc. Microsoft’s documented flow is to open Certification Authority, right-click the CA, choose All Tasks, and then select Renew CA Certificate.
How to think about reusing keys versus generating new keys. Microsoft says reusing the existing key pair keeps the process simpler, while a new key pair introduces more certificate chain changes.
How to distribute the renewed root certificate. Microsoft documents importing trusted root certificates through Computer Configuration - Policies - Windows Settings - Security Settings - Public Key Policies in Group Policy.
How to speed up client trust updates. Microsoft says clients can receive the new settings after restart or by running gpupdate /force.
This episode is especially useful for PKI admins, Windows admins, and homelab operators who want a safe, repeatable Root CA renewal process without breaking client trust. Microsoft Q&A guidance also notes that domain-joined clients can receive published root certificates through AD and Group Policy processing, though it may take time to propagate naturally.
Don’t forget to like, subscribe, and hit the bell for more content.
#ADCS #PKI #WindowsServer
Follow me on X: https://l.samayas.eu/jo3eaYEf3E?P=YT&...
Buy me a Coffee: https://l.samayas.eu/jX6xL7EWhd?P=YT&...
Studio Equipment
Camera Sony Alpha ZV-E10 II: https://l.samayas.eu/k7y90TREl0?P=YT&...
Secondary Camera Obsbot Tail Air: https://l.samayas.eu/iFQu9WfmCw?P=YT&...
Elgato Prompter: https://l.samayas.eu/fHVrqqXtSc?P=YT&...
Microphone Rode Wireless GO II: https://l.samayas.eu/afBINjiBXN?P=YT&...