Certificate Authority - Expired certificate problems


when trying renew iis ssl our certificate authority received access denied error. logged on our ca server , found our ca certificate due expire in april (less 6 months away) , assumed causing ca not issue new certificate less year.

we tried renew our ca certificate threw error (still looking exact error message). in event log had following error:

event id 58 - a certificate in chain ca certificate 0 britannia operator limited has expired.  a required certificate not within validity period when verifying against current system clock or timestamp in signed file. 0x800b0101 (-2146762495).

after more reading pointed towards pkiview , able see several issues:

under root of our ca name found following conditions:

"cdp location #1" - expiring

"deltacrl location #1" - expired

i ran "manage ad containers" , under "certification authorities container" we're seeing 2 objects our ca name, once of has status of "not time valid" , other "ok". cdp tab confirms above status of cdp/deltacrl includes 3rd basecrl we're assuming legacy configuration (points old server , expired).

one interesting thing noticed under "aia container" tab certificates 0 - 3 listed should seeing new (4th) certificate listed assume?

my best guess ever reason renewal of ca failed update db , therefore whole system confused due lack of new cert?

what should next step here? i'm off more forum trawling figured worth asking here see if can point me in right direction.

many thanks,

simon


-simon

this resolved, delta crl returned "ok" status end of day. morning able re-publish ca using certutil. mentioned above, no longer able renew certificates continue work , once expired create new certificates new ca.

i've made sure expiry date has been put in several calenders make sure doesn't re-occur :)

regards

simon


-simon



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2