289769a601
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s
78 lines
2.5 KiB
Markdown
78 lines
2.5 KiB
Markdown
---
|
|
tags:
|
|
- Active Directory
|
|
- Certificate Services
|
|
- PKI
|
|
---
|
|
|
|
## Purpose
|
|
Publish the root and subordinate CA revocation lists for the documented two-tier Active Directory certificate environment. The Root CA and HTTP distribution point must already be configured as described in the certificate deployment.
|
|
|
|
## CRL Publishing and Maintenance
|
|
CRLs must be generated and published on a recurring basis. If a CRL expires, certificate validation may fail even if the CA services themselves are running.
|
|
|
|
### Root CA CRL Publishing
|
|
Because the Root CA is offline, periodically bring it online only long enough to generate a new CRL and copy it to the HTTP distribution point.
|
|
|
|
On `LAB-CA-01`:
|
|
|
|
```powershell
|
|
certutil -crl
|
|
```
|
|
|
|
Copy the generated CRL from:
|
|
|
|
```text
|
|
C:\Windows\System32\CertSrv\CertEnroll\
|
|
```
|
|
|
|
to the IIS publication directory on `LAB-CA-02`:
|
|
|
|
```text
|
|
C:\inetpub\wwwroot\pki\
|
|
```
|
|
|
|
Validate:
|
|
|
|
```powershell
|
|
Invoke-WebRequest http://pki.bunny-lab.io/pki/BunnyLab-RootCA.crl
|
|
```
|
|
|
|
### Subordinate CA CRL Publishing
|
|
On `LAB-CA-02`:
|
|
|
|
```powershell
|
|
certutil -crl
|
|
```
|
|
|
|
Copy or confirm the Subordinate CA CRL exists in:
|
|
|
|
```text
|
|
C:\inetpub\wwwroot\pki\
|
|
```
|
|
|
|
Validate the URL from a domain-joined system.
|
|
|
|
### Operational Monitoring
|
|
Monitor CRL expiration and publication. Certificate validation failures can occur if CRLs expire, even if certificates themselves have not expired.
|
|
|
|
Recommended operational tasks:
|
|
|
|
- Track Root CA CRL expiration.
|
|
- Track Subordinate CA CRL expiration.
|
|
- Verify HTTP CRL URLs after each publication.
|
|
- Keep the Root CA offline except during controlled maintenance windows.
|
|
- Document the expected CRL filenames generated in `C:\Windows\System32\CertSrv\CertEnroll\`.
|
|
|
|
!!! abstract "Raw Unprocessed/Unimplemented Steps"
|
|
Publish CRLs regularly, configure overlap periods, and monitor expiration. Enable Delta CRLs on the Subordinate CA, but not on the Root.
|
|
Security Recommendations
|
|
|
|
- Harden CA servers; limit access to PKI admins.
|
|
- Use BitLocker or HSM for key protection.
|
|
- Monitor issuance and renewals with audit logs and scripts.
|
|
|
|
## Related Documentation
|
|
- [Certificate Services Deployment](<../../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Confirm the CA names, publication paths, and HTTP distribution point.
|
|
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|