Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX 525 version 6.2(2) SCEP RA certificates W2K


I have a problem with renewing RA certificates.

I discovered after i reinstalled mscep that it's possible to modify the validity period of personal certificates in command prompt on CA server:

C:\certutil -setreg ca\ValidityPeriodUnits x

where x = validity of issue certificate (years).

But I have already on CA and PIX both old RA certificates with old validity (1 year and they will expire soon) and i want to use the certificates issued with the old ones RA.

So if it's possible, how can i renewing validity period of RA?

Thank you in advance,


Cisco Employee

Re: PIX 525 version 6.2(2) SCEP RA certificates W2K

You just need to re-enroll the PIX to the cert server, so do what you did initially to get it all working, something like the following:

ca authenticate

ca enroll

ca save all

assuming that you still have the "ca identity" and "ca configure" commands in your config.

New Member

Re: PIX 525 version 6.2(2) SCEP RA certificates W2K


First of all thanks for answering me promptly.

After the steps you told me to follow on the PIX, the certificate the PIX will receive will contain the old RA certificates (existing now on the W2k CA server to) wich will soon expire.

So what should with this RA certificates on W2k CA server?

I want my old issued certificates (~ 150) to go on functioning.

Thank you so much,