Knowledge Base

XCLN: How Expired Encryption Key Pairs Work

Article ID: 152686

Article Last Modified on 8/16/2005


APPLIES TO


This article was previously published under Q152686

SUMMARY

By default, the Key Management Server in Microsoft Exchange Server provides public/private key encryption pairs that expire after 18 months. This cannot be changed.

MORE INFORMATION

You can still read messages encrypted with your older key pairs. A history of your encryption key pairs is maintained in both the .EPF file for client use, as well as in the KM Server database for key escrow purposes.

Old signatures will fail verification with the following error message:
A Signature has expired error.
However, all of the other conditions (message not altered, signature not suspended, etc.) will pass.

Keywords: kbother KB152686