Why did my Subordinate Issuing CA CRL expire?


hi,

we have 2-tier pki 2 subordinate issuing cas crlperiod of days , crlperiodunits of 14 me says publish new crl every 14 days.  found crl expired yesterday caused issues clients had certs issued ca.  issued 'certutil -crl' and a new crl published http site , ad.  other subordinate issuing ca's crl set same way , renews no problem.  suggestions on why crl did not renew?


thanks help! sdedot

that active directory ldap error caused publish process fail. can see if there other ad related error messages. have been transient issue won't repeat, if does, should preventing machine reaching domain.

mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. connect mark @ http://www.pkisolutions.com



Windows Server  >  Security



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

DFSR RPC replication errors 5014 1726 with large files over VPN

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B