Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Current Certificate Authorities

Server Configuration

The following are the preferred Certificate Authorities registered with the Austin Active Directory and the assocated test domainsfor internal certificates in the respective environments:

Server

Domain

CA Name

DFS Group

Key Length

Hash

Status

Purpose

Public

ServerNotesca-ext-p01Austin External 2015 SHA256Production (deprecated)External SHA2 certificatescertificates.austin

URL

aad-cart-p01

n/a

Austin-CA-Root-2022

n/a

4096

SHA384

Production

offline root CA

certificates.austin.utexas.edu

aad-case-p01

austin.utexas.edu

Austin-CA-Prod-2022

AAD-PKI

4096

SHA384

Production

issuing CA for prod

certificates.austin.utexas.edu

aad-case-q01

adqual.utexas.edu

Austin-CA-Qual-2022

AAD-PKI

4096

SHA384

Qual

issuing CA for qual

certificates.adqual.utexas.edu

aad-case-t01

adtest.utexas.edu

use

Austin-CA-

2016-Prod instead

Test-2022

AAD-PKI

4096

SHA384

Test

issuing CA for test

certificates.adtest.utexas.edu

Deprecated Certificate Authorities 

The following are active Certificate Authorities that are still active but no longer the preferred CA for the respective environment:

Server

Domain

CA Name

DFS Group

Key Length

Hash

Status

Purpose

Public URL

ca-root-p01

austin.utexas.edu

Austin-CA-2016-Prod

AUSTIN-PKI

2048

SHA256

Production

SHA2 certificates for prod

certificates.austin.utexas.edu

 

ca-root-q01

cds.utexas.edu

Austin-CA-2016-Qual

CDS-PKI

2048

SHA256

Test

SHA2 certificates for qual

certificates.cds.utexas.edu

 

ca-root-t01

adtest.utexas.edu

Austin-CA-2016-Test

ADTEST-PKI

2048

SHA256

Test

SHA2 certificates for

test

adtest

certificates.adtest.utexas.edu

 ca02austin

ca-root-q02

adqual.utexas.edu

External Certificate Authority SHA1ExpiredExternal certificates

Austin-CA-2018-Qual

ADQUAL-PKI

2048

SHA256

Qual

SHA2 certificates for adqual

certificates.

austin

adqual.utexas.edu

 ca03Austin Root Certificate Authority SHA1Production (deprecated)Root certificate onlycertificates.

Retired Certificate Authorities 

The following are the Certificate Authorities that are no longer in production use.

...

Server

Domain

CA Name

DFS Group

Key Length

Hash

Status

Purpose

Public Server

ca-ext-p01

austin.utexas.edu

 ca04Austin Subordinate Certificate Authority SHA1Production (deprecated)Issuer for normal certificatescertificates.

Austin External 2015

n/a

2048

SHA256

Retired

External SHA2 certificates

self

ca02

austin.utexas.edu

austin.utexas.edu

 ca05Austin Disk

External Certificate Authority

n/a

 certificates.

2048

SHA1

ProductionIssuer for disk IPsec certificates

Retired

External certificates

self

ca03

austin.utexas.edu

 ca06

Austin

External

Root Certificate Authority

n/a

 

2048

SHA1

Production (deprecated)External certificatescertificates.

Retired

Root certificate only

self

ca04

austin.utexas.edu

 

Assigned Certificate Templates

ServerCertificate Templates
ca-root-p01 
ca-root-q01 
ca-root-t01 

Naming Conventions

Current (as of 2016)

Austin CAs should confirm to the following naming conventions:

...

Austin Subordinate Certificate Authority

n/a

2048

SHA1

Retired

Issuer for normal certificates

self

ca05

austin.utexas.edu

Austin Disk Certificate Authority

n/a

2048

SHA1

Retired

Issuer for Austin Disk client certificates

self

ca06

austin.utexas.edu

Austin External Certificate Authority

n/a

2048

SHA1

Retired

External certificates

self