CDP and AIA need to be updated in AD for Offline Root CA
i have 2 tier pki infrastructure. when running pkiview.msc find the cdp , aia locations of offline rootca has typo. need update cdp , aia in ad offline rootca.
i not sure how this. other intermediate ca's report ok. offline rootca shows error.
how republish cdp , aia offline rootca? have reissue certs intermediate ca's once corrected rootca cdp , aia?
b.
i found easier answer fix problem cdp location. cdp url mistyped on root ca iis site location online issuing subordinate ca. placed copy of root crl , root certificate on server , using online sub ca additional third location obtain root cert (aia location) , cdp. using publically available site primary, ad, then, lastly, the iis location.
since internal able create cname record mistyped url points correct record of sub ca. caused pki view able resolve cdp , aia url correct iis location.
so, if happens else , find late change, , not want have go through re-deploying ca's, can manipulate dns resolution fix lookup issue. can proceed upgrade @ later date , decommission. old sub ca's after deploying new ca's. hope helps.
brian
Windows Server > Security
Comments
Post a Comment