Files
docs/workflows/Identity and Certificates/Certificates/Publish and Maintain Certificate Revocation Lists.md
nicole 289769a601
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s
Restructured Documentation
2026-09-05 14:08:43 -06:00

2.5 KiB

tags
tags
Active Directory
Certificate Services
PKI

Purpose

Publish the root and subordinate CA revocation lists for the documented two-tier Active Directory certificate environment. The Root CA and HTTP distribution point must already be configured as described in the certificate deployment.

CRL Publishing and Maintenance

CRLs must be generated and published on a recurring basis. If a CRL expires, certificate validation may fail even if the CA services themselves are running.

Root CA CRL Publishing

Because the Root CA is offline, periodically bring it online only long enough to generate a new CRL and copy it to the HTTP distribution point.

On LAB-CA-01:

certutil -crl

Copy the generated CRL from:

C:\Windows\System32\CertSrv\CertEnroll\

to the IIS publication directory on LAB-CA-02:

C:\inetpub\wwwroot\pki\

Validate:

Invoke-WebRequest http://pki.bunny-lab.io/pki/BunnyLab-RootCA.crl

Subordinate CA CRL Publishing

On LAB-CA-02:

certutil -crl

Copy or confirm the Subordinate CA CRL exists in:

C:\inetpub\wwwroot\pki\

Validate the URL from a domain-joined system.

Operational Monitoring

Monitor CRL expiration and publication. Certificate validation failures can occur if CRLs expire, even if certificates themselves have not expired.

Recommended operational tasks:

  • Track Root CA CRL expiration.
  • Track Subordinate CA CRL expiration.
  • Verify HTTP CRL URLs after each publication.
  • Keep the Root CA offline except during controlled maintenance windows.
  • Document the expected CRL filenames generated in C:\Windows\System32\CertSrv\CertEnroll\.

!!! abstract "Raw Unprocessed/Unimplemented Steps" Publish CRLs regularly, configure overlap periods, and monitor expiration. Enable Delta CRLs on the Subordinate CA, but not on the Root. Security Recommendations

- Harden CA servers; limit access to PKI admins.
- Use BitLocker or HSM for key protection.
- Monitor issuance and renewals with audit logs and scripts.