A system using digital certificates having overlapping validity intervals.
The overlapping certificates can be used in a hierarchical certificate
authorities network in order to obtain benefits such as to increase the
usage of all the certificates in the certificate chain; reduce/eliminate
the certificate updates/downloads to a large population; only replace the
minimum number of certificates in the trust hierarchy to re-establish the
certificate chain; reduce the complexity of maintaining certificate
nesting in certificate generation process; reduce the risk of service
interruption; and control the extent of older technology in circulation
and to reduce the risk associated with older products being more
susceptible to attack. The certificate renewal process of a preferred
embodiment is described.