outdated certificates in CRL on Windows 2008-CA


i have migrated win2k-ca windows 2008 server , have problem crl has grown 3kb 150kb.

when have closer on revoked certifiicates in crl see lots of certificates expired still in crl.

i set crlflag -crlf_publish_expired_cert_crls, after 10 12 new crl's generated old certificates still in list.

any ideas or on this?

thanks

wolfgang

the expired+revoked certificates should not appear in crl unless are explicitly marked published regardless expiration. check if certificate is explicitly flagged published in crl after expire, add column "publish expired certificate in crl" in certification authority management mmc.

/hasain




Windows Server  >  Security



Comments

Popular posts from this blog

Schannel Issue

Indexing Server

oclist /xml or /?