--- tags: - Active Directory - Certificate Services - PKI --- ## Purpose Publish the root and subordinate CA revocation lists for the documented two-tier Active Directory certificate environment. The Root CA and HTTP distribution point must already be configured as described in the certificate deployment. ## CRL Publishing and Maintenance CRLs must be generated and published on a recurring basis. If a CRL expires, certificate validation may fail even if the CA services themselves are running. ### Root CA CRL Publishing Because the Root CA is offline, periodically bring it online only long enough to generate a new CRL and copy it to the HTTP distribution point. On `LAB-CA-01`: ```powershell certutil -crl ``` Copy the generated CRL from: ```text C:\Windows\System32\CertSrv\CertEnroll\ ``` to the IIS publication directory on `LAB-CA-02`: ```text C:\inetpub\wwwroot\pki\ ``` Validate: ```powershell Invoke-WebRequest http://pki.bunny-lab.io/pki/BunnyLab-RootCA.crl ``` ### Subordinate CA CRL Publishing On `LAB-CA-02`: ```powershell certutil -crl ``` Copy or confirm the Subordinate CA CRL exists in: ```text C:\inetpub\wwwroot\pki\ ``` Validate the URL from a domain-joined system. ### Operational Monitoring Monitor CRL expiration and publication. Certificate validation failures can occur if CRLs expire, even if certificates themselves have not expired. Recommended operational tasks: - Track Root CA CRL expiration. - Track Subordinate CA CRL expiration. - Verify HTTP CRL URLs after each publication. - Keep the Root CA offline except during controlled maintenance windows. - Document the expected CRL filenames generated in `C:\Windows\System32\CertSrv\CertEnroll\`. !!! abstract "Raw Unprocessed/Unimplemented Steps" Publish CRLs regularly, configure overlap periods, and monitor expiration. Enable Delta CRLs on the Subordinate CA, but not on the Root. Security Recommendations - Harden CA servers; limit access to PKI admins. - Use BitLocker or HSM for key protection. - Monitor issuance and renewals with audit logs and scripts. ## Related Documentation - [Certificate Services Deployment](<../../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Confirm the CA names, publication paths, and HTTP distribution point. - [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.