Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ACE SSL Key & Certificate rules

hi,

- Is it necessary that every CSR (different common names) use/generate a unique key or a single key can be used for multiple CSRs (i.e. different common names).

1 ACCEPTED SOLUTION

Accepted Solutions

Re: ACE SSL Key & Certificate rules

I dont see why it shouldn't work but its definitely not recommended and is not a good idea.

From Carlisle Adams' PKI book, recommending against putting the same key

in multiple certs:

"It is too easy to "slip up" and not hold all other important aspects of

these multiple certificates constant. [...] If a single public key is

contained in multiple certificates and the private key is compromised (or

other circumstances occur that require revocation), it must be "remembered"

(or discovered) which certificates contain this key so that they may all be

revoked. [...] Having the same public key in multiple certificates can

complicate the administrative processes involved in certificate management."

http://www.amazon.com/exec/obidos/ASIN/0672323915/104-7451273-2110334

Syed Iftekhar Ahmed

2 REPLIES

Re: ACE SSL Key & Certificate rules

I dont see why it shouldn't work but its definitely not recommended and is not a good idea.

From Carlisle Adams' PKI book, recommending against putting the same key

in multiple certs:

"It is too easy to "slip up" and not hold all other important aspects of

these multiple certificates constant. [...] If a single public key is

contained in multiple certificates and the private key is compromised (or

other circumstances occur that require revocation), it must be "remembered"

(or discovered) which certificates contain this key so that they may all be

revoked. [...] Having the same public key in multiple certificates can

complicate the administrative processes involved in certificate management."

http://www.amazon.com/exec/obidos/ASIN/0672323915/104-7451273-2110334

Syed Iftekhar Ahmed

New Member

Re: ACE SSL Key & Certificate rules

Always use a unique key per CSR. while it it technically possible the prior poster gave many of the reasons why it is a bad idea and there are many others. Just assume a key pair is unique to a CSR.

149
Views
0
Helpful
2
Replies
CreatePlease login to create content