ITS Service Status Report

Scheduled Maintenance

Updated UMROOT Certificates

Services Affected: Identity and Access Management Application Services, Active Directory Certificate Services

Start Time: 09/03/2023 10:00 pm

Anticipated End Time: Unknown

Issue Symptoms: Unknown

As previously shared, a new Certificate Authority (CA) has been established and new Root and Intermediate certificates are now being issued for the UMROOT Active Directory domain. 

To best protect University systems and data, the IAM Team will begin revoking old certificates starting September 25, 2023

Action required

Units that have connections to Active Directory should download and install the newly issued certificates as soon as possible. This includes Linux servers and other network devices that may need to import the new certificate chain manually. The new certificates are available at Active Directory (UMROOT) Certificates.

  • Import the new CA root and intermediate as trusted sources (if this wasn't done already automatically).

  • If someone has pointed a Group Policy Object (GPO) to the old CA Certificate, they need to point it to a new CA Certificate.

  • If you worked with ITS in the past to create a certificate template, you will need to coordinate with ITS to ensure the template is available on the new CA and that your clients are pointed at the new infrastructure. For this type of support, open a ticket to the ITS Active Directory team

If you have a critical issue that you think is related to a certificate problem or need any assistance with downloading or installing a new certificate, open a ticket to the ITS Active Directory team.

Who is Impacted? Users authenticating to UMROOT Active Directory

Next Update: 9/25 EOD

Technical Details

Service Type: Production

Report Additional Impacts

Contact the ITS Service Center for more information or to report additional impacts.