Why did my Subordinate Issuing CA CRL expire?


hi,

we have 2-tier pki 2 subordinate issuing cas crlperiod of days , crlperiodunits of 14 me says publish new crl every 14 days.  found crl expired yesterday caused issues clients had certs issued ca.  issued 'certutil -crl' and a new crl published http site , ad.  other subordinate issuing ca's crl set same way , renews no problem.  suggestions on why crl did not renew?


thanks help! sdedot

that active directory ldap error caused publish process fail. can see if there other ad related error messages. have been transient issue won't repeat, if does, should preventing machine reaching domain.

mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. connect mark @ http://www.pkisolutions.com



Windows Server  >  Security



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...