Removing expired Certificate Authority certificates from the trusted certificate list (2024)

Over time some trusted Certificate Authority (CA) certificates will expire and will no longer be trusted by the Symantec Messaging Gateway (SMG). While there is no harm in leaving the expired certificates in the trusted CA certificate bundle some administrators may want to remove the expired certificates from the SMG control center.

To remove expired CA certificates:

  1. Log on to the SMG control center as an administrator and navigate to Administration > Settings > Certificates
  2. Select the Certificate Authority tab
  3. Click the Backup button and save the file
  4. Click the Restore button
  5. Browse to the backup file you just created, select it, and click "Open"

The expired certificates will not be restored, effectively removing them from the CA certificate list. The following message is displayed in the Control Center after a successful import:

"CA Certificates restored successfully. Note that expired certificates are not imported."

Removing expired Certificate Authority certificates from the trusted certificate list (2024)

FAQs

How to remove expired certificates from certificate authority? ›

To remove expired CA certificates:
  1. Log on to the SMG control center as an administrator and navigate to Administration > Settings > Certificates.
  2. Select the Certificate Authority tab.
  3. Click the Backup button and save the file.
  4. Click the Restore button.
  5. Browse to the backup file you just created, select it, and click "Open"
Oct 9, 2023

How to remove certificate from trusted root Certification Authority? ›

Step by Step
  1. Go to the Home screen.
  2. Tap Settings > Additional Settings > Privacy > Trusted credentials.
  3. Find the System tab and tap on it. ...
  4. Tap the Root CA certificate name you wish to remove. ...
  5. On the Details screen, tap on the Disable button. ...
  6. Tap OK to proceed with the Root CA Certificate deletion.

How do I remove an expired SSL certificate? ›

Locate and right-click on the certificate you wish to remove. Click on Properties and then in the General tab, click on Disable all purposes for this certificate in the Certificate purposes section. Hit Apply and restart your server to complete the removal process.

How do I remove old certificate authority server? ›

  1. Summary.
  2. Step 1 - Revoke all active certificates that are issued by the enterprise CA.
  3. Step 2 - Increase the CRL publication interval.
  4. Step 3 - Publish a new CRL.
  5. Step 4 - Deny any pending requests.
  6. Step 5 - Uninstall Certificate Services from the server.
  7. Step 6 - Remove CA objects from Active Directory.
Feb 25, 2024

Should you revoke expired certificates? ›

Letting it expire is certainly an option, but it's not a wise one. Similarly, you are allowed to revoke your certificate, although that solution should only be employed if you are closing your business or if you have recently suffered a breach that calls for extensive security updates.

What happens when a certificate authority expires? ›

CA certificates have a fixed lifetime, or validity period. When a CA certificate expires, all of the certificates issued directly or indirectly by subordinate CAs below it in the CA hierarchy become invalid. You can avoid CA certificate expiration by planning in advance.

How to remove a trusted certificate authority from computers in the domain? ›

Expand the "Services", and then expand "Public Key Services". Select the "AIA" node. In the right-hand pane, locate the "certificateAuthority" object for your Certification Authority. Delete the object.

How do I disable trusted certificates? ›

Go to the Exclusions pane. Find Trusted Certificates section and select the trusted certificates to be removed. Click the Delete button and the Remove Trusted Certificate dialog window will appear. Click Confirm to remove the selected entries.

How to clear certificate cache? ›

In the search field please type in “cmd” and press the Enter key. You should see the C:\Windows\system32\cmd.exe dialog box appear (windows box with the black background) like below. In the C:\users\(your username here)>prompt, type in the following: certutil –urlcache * delete and then press the Enter key.

How do I delete old CAC certificates in Chrome? ›

To remove the certificate from the browser, follow these steps:
  1. Open Google Chrome, click the Customize and control Google Chrome icon (the three vertical dots ) > go to Settings > at the left margin, click Privacy and security > click Security.
  2. Under Advanced, click Manage certificates.

How do I revoke a certificate in Windows? ›

How to Revoke a Certificate. If a certificate has been compromised or you have another reason to remove it from circulation, right-click on it in the Issued list, go to All Tasks, then choose Revoke Certificate. The interface will ask you for a reason code and a timestamp.

How to remove certificate from trusted root Certification Authority windows 11? ›

Press Windows Key + R Key together, type certmgr. msc and hit enter. You will get a new window with the list of Certificates installed on your computer. Locate for the certificate you want to delete and then click on Action button then, click on Delete.

How do I remove a certificate from Keystore? ›

Use the keytool -delete command to delete an existing certificate.

Top Articles
Latest Posts
Article information

Author: Maia Crooks Jr

Last Updated:

Views: 5628

Rating: 4.2 / 5 (63 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Maia Crooks Jr

Birthday: 1997-09-21

Address: 93119 Joseph Street, Peggyfurt, NC 11582

Phone: +2983088926881

Job: Principal Design Liaison

Hobby: Web surfing, Skiing, role-playing games, Sketching, Polo, Sewing, Genealogy

Introduction: My name is Maia Crooks Jr, I am a homely, joyous, shiny, successful, hilarious, thoughtful, joyous person who loves writing and wants to share my knowledge and understanding with you.