outdated certificates in CRL on Windows 2008-CA
i have migrated win2k-ca windows 2008 server , have problem crl has grown 3kb 150kb.
when have closer on revoked certifiicates in crl see lots of certificates expired still in crl.
i set crlflag -crlf_publish_expired_cert_crls, after 10 12 new crl's generated old certificates still in list.
any ideas or on this?
thanks
wolfgang
the expired+revoked certificates should not appear in crl unless are explicitly marked published regardless expiration. check if certificate is explicitly flagged published in crl after expire, add column "publish expired certificate in crl" in certification authority management mmc.
/hasain
Windows Server > Security
Comments
Post a Comment