new subordiante's CRLs listed in AD despite not having LDAP CDPs


when standing new subordinate ca did not create ldap crl extensions. below did, note uris have been truncated fit other properties. i'm sending crls file share hosts them on web. easy manage. question, how come in pkiview under cdp container see base , delta crls? i've confirmed exits under cn=cdp.  this has become problem (or think) delta has become expired , don't have ldap cdp extension update it. pretty base crl's overlap period laps , pkiview show them both expired. did go wrong, required have ldap cdp extension? 

when ca service starts first time, there default ldap url (which change later when configure ca settings) , ca automatically publishes first crl. won't updated anymore, because configuration not use ldap.

vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file