Organization Certificate Expired - PGP Universal Server
| Article:TECH149187 | | | Created: 2008-07-08 | | | Updated: 2011-02-07 | | | Article URL http://www.symantec.com/docs/TECH149187 |
Problem
When viewing the Organization Keys on the Organization card of the PGP Universal Server, you receive the following message.
Organization Certificate Expired
The organization certificate has expired. Please remove, replace, or regenerate it as soon as possible.
Solution
An Organization Certificate is required for S/MIME support. You can only have one Organization Certificate attached to your Organization Key. You will not be able to restore from a backup with more than one Organization Certificate associated with your Organization Key.
The Organization Key will automatically renew itself one day before its expiration date. However, the Organization Certificate must be regenerated manually.
| Note: A self-signed Organization Certificate will have the same expiration date as the Organization Key, unless the Organization Key is set never to expire. If the Organization Key will never expire, the Organization Certificate will expire 10 years from the date you generate it. You must regenerate the Organization Certificate before it expires and distribute the new Certificate to anyone who uses your old Organization Certificate as a trusted root CA. |
The PGP Universal Server will automatically generate certificates as well as keys for new internal users created after you import or generate an Organization Certificate. All internal users will receive a certificate added to their keys within 24 hours. However, the old Organization Certificate will remain on users keys until the certificate expires.
When a Organization Certificate expires, you have several options to resolve the issue:
- Create a self-signed Organization Certificate. Unfortunately, a self-signed Organization Certificate will not be universally recognized, so PGP Corporation recommends using a certificate from a recognized Certificate Authority (CA). Self-signed X.509 Organization Certificates are version 3.
- Create a Certificate Signing Request for a certificate authorized by an existing CA. When you receive the certificate back from the CA as a file, you will need to import that file.
- Import an existing certificate to use as your Organization Certificate. Imported X.509 certificates must be version 3.
To generate a Self-signed certificate or a Certificate Signing Request:
- Login to the PGP Universal Server.
- Click the Organization card.
- Select the + icon in the action column of the Organization Certificate row.
- Enter your information for the certificate (Common Name, Contact Email, etc.).
- Click Generate Self-signed for a self-signed certificate or Generate CSR to create Certificate Signing Request.
To create a Certificate Signing Request (CSR):
|
To import a certificate:
- Login to the PGP Universal Server.
- Click the Organization card.
- Click the icon in the Import column of the Organization Certificate row.
- Copy the certificate you want to be your Organization Certificate.
- Paste the text into the Certificate Block box.
- Click Save.
|
|
Legacy ID
1003
Article URL http://www.symantec.com/docs/TECH149187
Terms of use for this information are found in Legal Notices









Thank you.