Auto Enrollment Proxy (AEP)
When issuing a cert via AEP, the validity period is always set to 1 year, no matter the validity specified in the extension profile/Jurisdiction.
Certificates are assigned validity from the Minimum certificate validity expiry policy when issued through the AEP.
If certificate expiry policy set as profile based, then certificates are issued with the validity of profile which is configured under aep.xuda page. (It will not take the validity of profile configured under "Profile Choices").
AEP xuda page configured with TTL value as 1 year.
Since we are using same signer code for AEP certificate issuance and there are no validAfter or validUntil values for certificate from AEP, apache takes this TTL value for validity. So that, it is working with minimum validity period (if min. validity > 1year) of expiry policy.
The AEP Xuda page is configured with the time-to-live (TTL) value as one year, which is set as the validity for the certificate. As all certificates are set with this one-year validity period, users cannot have certificates with greater or lesser validity period.
This problem is fixed in RSA Certificate Manager 6.8 build519. The validity period is now taken from the Certificate Expiry Policy configuration.
CERTMGR-3774
Related Articles
How to set RSA ACE/Server user password lifetime to greater than 3 years 4Number of Views New Change Requests become stuck at every Approval Node regardless of Approval status in RSA Identity Governance & Lifecycle 162Number of Views How to determine the RSA Authentication Manager 8.x hardware platform 547Number of Views Offline logon failure then loop back to login screen RSA Authentication Agent 7.3.3 [99] for Windows 144Number of Views Enable SSH using the command line on RSA Authentication Manager 8.4 and up 343Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide