Importance of AD CDP Container


hi

i've implemented 2008 r2 2 tier pki testing.

i opted single http url aia & cdp in issued certificates. used standard parctice build online enterprise ca's & configured post installation script. aia & cdp config follows:

certutil -setreg ca\crlpublicationurls "65:%windir%\system32\certsrv\certenroll\%%3%%8%%9.crl\n6:http://mycompany/crl/%%3%%8%%9.crl"

certutil -setreg ca\cacertpublicationurls  "1:%windir%\system32\certsrv\certenroll\%%3%%4.crt\n2:http://mycompany/aia/%%3%%4.crt"

scheduled script copies actual files web server when new crl published.

so far good...

when use enterprise pki view manage ad containers notice cdp container contains base & delta crl's issuing ca's. closer examination shows these first base & delta crl's issued ca's. expired / expiring & have couple of questions clarification:

1. think these exist because ca published them default when service started first time, before post installation script modified locations. subsequent publication doesn't use location they're never updated. correct?

2. i'm concerned should publishing ldap location if it's not included in issued certificates. other keep pki view happy there technical reason so?

thanks


douks

1. true, way describing it.

2. no, never need publish crl ldap if not actively used cdp in issued certificates. pki view going happy without because enumerates current config of ca , list/verifies cdp urls included in that.

/hasain



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group