Hello,
I am trying to sort something out with certifier key rollover.
I am planning a rollover of the organization certifier and subsequently all OUs, servers and users.
So now I do not quite understand how it works for users with their ID in IDVault. I need to rollover the cross certificate for the vault, don't I? But then the users cannot upload anymore to the vault, because they don't know the (cross-)certifier.
Rolling over the users first, also will not work because the rolled over user ids do not know the IDVaults (old) (cross) certifier.
How is this supposed to work? Transparently for the user, that is. Did I understand something wrong?
Thank you,
Manuel