Certificate Migration query


hi guys,

i have migrated our enterprise ca windows 2000 windows 2008 r2 dc.  i have followed adcs upgrade , migration guide , completed of steps successfully.  however, confused 1 particular setting.  i right click ca certname , click properties.  then, on general tab click view certificate.  i click on details tab , when scroll down crldistributionpoints, there no locations point new server.  is normal?

currently there locations old ca server.  i have modified crldistributionpoints in extensions tab point old server existing certificates.  these settings original imported certificate old ca.

any appreciated

kind regards,

the cdp , aia information in ca certificate can ignored, cdp , aia in root ca certificate windows 2000 did , not have technical effect on system.

to sure old certificates can crl checked need configure old cdp urls publication only. means ca can use new set of cdp urls include in newly issued certificates , keeps publishing crls new , old locations equally without including old cdp locations in new certificates.

once old certificates has been expired or replaced can remove old crl distribution points!

/hasain



Windows Server  >  Security



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...