new subordiante's CRLs listed in AD despite not having LDAP CDPs
when standing new subordinate ca did not create ldap crl extensions. below did, note uris have been truncated fit other properties. i'm sending crls file share hosts them on web. easy manage. question, how come in pkiview under cdp container see base , delta crls? i've confirmed exits under cn=cdp. this has become problem (or think) delta has become expired , don't have ldap cdp extension update it. pretty base crl's overlap period laps , pkiview show them both expired. did go wrong, required have ldap cdp extension?
vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.
Windows Server > Security
Comments
Post a Comment