CRL and delta publication issue


i believe know solution issue wanted input before make changes not touched previously. issue crl’s , deltas not automatically publishing distribution points.

we have offline root ca , 2 subordinate ca’s. each subordinate certificate has 4 distribution points. crl’s publish local ca, ldap, , copied to external http site automatic process. however, each ca unable update certificate on other ca.

i’ve attached screenshot shows crl distribution point. cdp have marked out server name in red 1 not being updated. based on have found because crl cannot updated via http must updated unc path i.e. file://<servername>\c$\windows\system32\certsrv\certenroll\<caname><crlnamesuffix><deltacrlallowed>

is correct?

if have follow question. if crl cannot http location, should http locations removed cdp?

yes. however, not use design. ca servers shall not run other roles except adcs service. means, no iis (web enrollment, http distribution points) shall served ca server. these must separate servers. suggest check blog post on designing cdp/aia extensions following best practices: https://www.sysadmins.lv/blog-en/designing-crl-distribution-points-and-authority-information-access-locations.aspx

vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.



Windows Server  >  Security



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...