When you set up the root Enterprise CA, you can specify how long the certificate will be valid before you must reissue itself another certificate. Ok, how do you specify the valid lifetime of certificates issued to users? Suppose the Root Certificate is valid for 5 years... how can define the lifespan of a certificate I wish to issue - for example an EFSRecoveryAgent - to a user to be valid for 3 years?