outdated certificates in CRL on Windows 2008-CA


i have migrated win2k-ca windows 2008 server , have problem crl has grown 3kb 150kb.

when have closer on revoked certifiicates in crl see lots of certificates expired still in crl.

i set crlflag -crlf_publish_expired_cert_crls, after 10 12 new crl's generated old certificates still in list.

any ideas or on this?

thanks

wolfgang

the expired+revoked certificates should not appear in crl unless are explicitly marked published regardless expiration. check if certificate is explicitly flagged published in crl after expire, add column "publish expired certificate in crl" in certification authority management mmc.

/hasain




Windows Server  >  Security



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B

DFSR RPC replication errors 5014 1726 with large files over VPN