2.5 KiB
tags
| tags | |||
|---|---|---|---|
|
Purpose
Publish the root and subordinate CA revocation lists for the documented two-tier Active Directory certificate environment. The Root CA and HTTP distribution point must already be configured as described in the certificate deployment.
CRL Publishing and Maintenance
CRLs must be generated and published on a recurring basis. If a CRL expires, certificate validation may fail even if the CA services themselves are running.
Root CA CRL Publishing
Because the Root CA is offline, periodically bring it online only long enough to generate a new CRL and copy it to the HTTP distribution point.
On LAB-CA-01:
certutil -crl
Copy the generated CRL from:
C:\Windows\System32\CertSrv\CertEnroll\
to the IIS publication directory on LAB-CA-02:
C:\inetpub\wwwroot\pki\
Validate:
Invoke-WebRequest http://pki.bunny-lab.io/pki/BunnyLab-RootCA.crl
Subordinate CA CRL Publishing
On LAB-CA-02:
certutil -crl
Copy or confirm the Subordinate CA CRL exists in:
C:\inetpub\wwwroot\pki\
Validate the URL from a domain-joined system.
Operational Monitoring
Monitor CRL expiration and publication. Certificate validation failures can occur if CRLs expire, even if certificates themselves have not expired.
Recommended operational tasks:
- Track Root CA CRL expiration.
- Track Subordinate CA CRL expiration.
- Verify HTTP CRL URLs after each publication.
- Keep the Root CA offline except during controlled maintenance windows.
- Document the expected CRL filenames generated in
C:\Windows\System32\CertSrv\CertEnroll\.
!!! abstract "Raw Unprocessed/Unimplemented Steps" Publish CRLs regularly, configure overlap periods, and monitor expiration. Enable Delta CRLs on the Subordinate CA, but not on the Root. Security Recommendations
- Harden CA servers; limit access to PKI admins.
- Use BitLocker or HSM for key protection.
- Monitor issuance and renewals with audit logs and scripts.
Related Documentation
- Certificate Services Deployment — Confirm the CA names, publication paths, and HTTP distribution point.
- Related Identity and Certificates Documentation — Find the connected deployments, procedures, and references for this subject.