Renewing a Certificate Authority

Renew a certificate authority (CA) when it nears expiration, whenever you need to update its certificate contents, or if it's been revoked because of a security breach of its certificate or its key.

Renewing a CA creates another CA version with new certificate contents and a new validity period. CA renewals happen manually. You can't automatically renew a CA by using renewal rules. Before you renew a CA, rotate the key that you use with the CA to ensure that the new CA version you create contains updated key material. For more information, see Rotating a Vault Key.