How to update Root CA certificate in KRA after it has been re-signed on the KCA
2 years ago
Originally Published: 2004-05-20
Article Number
000057495
Applies To
Keon Registration Authority 6.5.1
RSA Public Root Signing
Issue
How to update Root CA certificate in KRA after it has been re-signed on the KCA
Keon RA database not updated if target CA re-signed
If installing Root Chain in browser for updated root certificate and then logging into RA Admin, RA Admin does not display. But if you delete the certificate immediately above RA Admin, the problem is resolved.
Web server does not trust new root chain

Cause
The Root CA that has been re-signed is not updated in the KRA database. It contains the old Root certificate received during installation.
Resolution
This issue has been resolved in a hot fix to RSA Keon Registration Authority 6.5.1. Contact RSA Security Customer Support to request KRA 6.5.1 build 228 hot fix. In Keon RA 6.5.1 build228, the re-signed CA certificate is copied to the Keon RA database when the "Synchronize Target Jurisdiction" button on the Synchronize Jurisdiction page is clicked.