CDP Expired

Niven Peter 86 Reputation points
2020-08-04T07:41:52.52+00:00

Hi experts,

Upon checking, I have found out that CDP location is expired as below:-

15443-cdp.jpg

I have tried the following as stated in microsoft article as below:-

  1. certutil -CRL

Upon doing so, I can see the new .crl being generated in

C:\Windows\System32\certsrv\CertEnroll

  1. Then I did the following command, Certutil -f -dspublish CertificateFile.crl NetBiosNameofCAServer

However, it prompts out as below

15444-2.jpg

  1. After that, I restarted the ADCS service and launch pkiview.msc again but it still show as expired as in the 1st figure as above.

Am I missing some steps?

Peter

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,149 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Fan Fan 15,321 Reputation points Microsoft Vendor
    2020-08-05T00:53:31.587+00:00

    Hi,

    First of all i want to confirm that is it a 2 tier PKI with a offline CA and enterprise CA or a 1 tier PKI with only one enterprise CA?

    If in a 2 tier PKI, we need to publish the CRL for Offline Root CA manually step by step as following:

    15622-8052.jpg
    If in a 1 tier PKI,after publish the CRL, try to copy the new published CRL to the Web server, usually, under the copy \webserver.pki.com\C$\CertEnroll\
    If there are any progress, welcome to share here!
    Fan