Expired offline crl


my offline crl expired , of course certificate validation fails. generated new offline crl , copied url location certenroll. used pkiview tool check cdp locations. url location verifies. ldap location not because new crl has not been copied ad. here problem. attempted copy new crl using command certutil -dspublish name.crl -f. command completes successfully and says "the base crl added store". pkiview tool still says ldap cdp location still expired or contains expired crl. 
robert porter

hi,

 

thank post.

 

if understand correctly, there 2 cdp locations downloading offline crl: 1 ldap location , 1 http location. have publish latest crl ad (ldap location). however, pkiview tool still says status of ldap cdp location expired.

 

i tested command used publish crl , noticed command created new container (cn=-f) , published crl container instead of original container. example, if ldap cdp location cn=offlineca,cn=ca,cn=cdp,cn=public key services,cn=services,cn=configuration,dc=test,dc=local, command certutil -dspublish name.crl –f store crl in cn=offlineca,cn=-f (not cn=ca),cn=cdp,cn=public key services,cn=services,cn=configuration,dc=test,dc=local. cause of issue.

 

to publish crl expected location, please run certutil -dspublish -f name.crl (we need input –f parameter before file name). can verify location correct after type command , press enter.

 

after that, please refresh pkiview , check result. if issue persists, suggest checking following:

 

·         please check latest crl in certenroll folder , make sure valid (effective date, next update).

·         please check crldistributionpoint object in ad (the ldap cdp location) , make sure has been updated (whenchanged)

 

thanks. forward response.



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2