Certificate Migration query
hi guys,
i have migrated our enterprise ca windows 2000 windows 2008 r2 dc. i have followed adcs upgrade , migration guide , completed of steps successfully. however, confused 1 particular setting. i right click ca certname , click properties. then, on general tab click view certificate. i click on details tab , when scroll down crldistributionpoints, there no locations point new server. is normal?
currently there locations old ca server. i have modified crldistributionpoints in extensions tab point old server existing certificates. these settings original imported certificate old ca.
any appreciated
kind regards,
the cdp , aia information in ca certificate can ignored, cdp , aia in root ca certificate windows 2000 did , not have technical effect on system.
to sure old certificates can crl checked need configure old cdp urls publication only. means ca can use new set of cdp urls include in newly issued certificates , keeps publishing crls new , old locations equally without including old cdp locations in new certificates.
once old certificates has been expired or replaced can remove old crl distribution points!
/hasain
Windows Server > Security
Comments
Post a Comment