CRL and delta publication issue
i believe know solution issue wanted input before make changes not touched previously. issue crl’s , deltas not automatically publishing distribution points.
we have offline root ca , 2 subordinate ca’s. each subordinate certificate has 4 distribution points. crl’s publish local ca, ldap, , copied to external http site automatic process. however, each ca unable update certificate on other ca.
i’ve attached screenshot shows crl distribution point. cdp have marked out server name in red 1 not being updated. based on have found because crl cannot updated via http must updated unc path i.e. file://<servername>\c$\windows\system32\certsrv\certenroll\<caname><crlnamesuffix><deltacrlallowed>
is correct?
if have follow question. if crl cannot http location, should http locations removed cdp?
vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.
Windows Server > Security
Comments
Post a Comment