Renewing a Symantec Encryption Management Server Organization Certificate may result in duplicate client certificates being generated if the Organization Certificate was initially created in an earlier release.
The duplicate client certificates will be generated with the following upgrade paths:
SKM key mode
For example, prior to the Organization Certificate being renewed, a user using SKM key mode will have user certificates like this visible in the administration console:
After the Organization Certificate is renewed and the twice daily key renewal process has run on the server, a second signing certificate will be generated for the user:
GKM or CKM key mode
For a user using GKM or CKM key mode, prior to the Organization Certificate being renewed the user certificate will look like this:
After the Organization Certificate is renewed and the twice daily key renewal process has run on the server, a second certificate will be generated for the user:
This occurs because the default order of the attributes within the Subject and Issuer fields in the Organization Certificate differs depending on which release is being used.
To confirm this change:
An Organization Certificate generated in PGP Universal Server 2.x has the following order of attributes in the Subject and Issuer fields:
An Organization Certificate generated in Symantec Encryption Management Server (and PGP Universal Server) 3.0 to 3.3.2 MP13 has the attributes in the Subject and Issuer fields in reverse order compared to PGP Universal Server 2.x:
An Organization Certificate generated in Symantec Encryption Management Server 3.4 and above has the attributes in the Subject and Issuer fields in almost the same order as PGP Universal Server 2.x - the difference is that the OU and O fields are reversed:
The Issuer field of a client certificate is identical to the Subject field of its Organization Certificate.
If the order of attributes in the Organization Certificate's Subject field changes then a new client certificate is generated. This is because collectively the attributes in the Subject field of an Organization Certificate comprise the certificate's Distinguished Name.
When renewing client certificates, Symantec Encryption Management Server detects that the Organization Certificate has been replaced, rather than having its validity date extended.
Duplicate client certificates caused by these changes to the attribute order of the Organization Certificate are very unlikely to result in any issues. Note that the older duplicate client certificates will be deleted automatically once they have expired.
In Symantec Encryption Management Server 3.4 and above it is possible to avoid duplicates being generated because there is a setting that determines the default order of attributes in the Organization Certificate Subject and Issuer fields. There are three possible options. Please contact Support for further details:
In Symantec Encryption Management Server 3.3.2 MP13 and below, the only way to ensure compatibility when renewing an Organization Certificate originally created in PGP Universal Server 2.x is as follows: