Expired offline crl
robert porter
hi,
thank post.
if understand correctly, there 2 cdp locations downloading offline crl: 1 ldap location , 1 http location. have publish latest crl ad (ldap location). however, pkiview tool still says status of ldap cdp location expired.
i tested command used publish crl , noticed command created new container (cn=-f) , published crl container instead of original container. example, if ldap cdp location cn=offlineca,cn=ca,cn=cdp,cn=public key services,cn=services,cn=configuration,dc=test,dc=local, command certutil -dspublish name.crl –f store crl in cn=offlineca,cn=-f (not cn=ca),cn=cdp,cn=public key services,cn=services,cn=configuration,dc=test,dc=local. cause of issue.
to publish crl expected location, please run certutil -dspublish -f name.crl (we need input –f parameter before file name). can verify location correct after type command , press enter.
after that, please refresh pkiview , check result. if issue persists, suggest checking following:
· please check latest crl in certenroll folder , make sure valid (effective date, next update).
· please check crldistributionpoint object in ad (the ldap cdp location) , make sure has been updated (whenchanged)
thanks. forward response.
Windows Server > Security
Comments
Post a Comment