"CA certificate for this CRL has been revoked" error when checking CRL properties


hi all, have 2-tier pki hierarchy offline root (2012) , enterprise subordinate issuing ca (2008r2).

we had re-issue certificate subordinate ca include new aia details, , after process revoked old subordinate ca cert root. when issued new certificate subordinate ca republished root ca crl , copied relevant domain , published along installing new ca cert.

the issue whenever view properties of revoked certificates container in certification authority console (of subordinate ca), message "ca certificate crl has been revoked" key index of 0. no other entries exist crls or delta crls. checking pkiview shows no errors, , can view crl file (although doesn't complete, it's missing quite few revoked certificates in comparison certification authority console) , can publish new crl without errors.

no error messages in event log either , far can tell else working fine, have doubts whether revocation working though due issue.

any ideas? in advance


did perhaps renew subordinate ca certificate same key?

if yes think issue follows:

if key has not been changed on renewal sub ca keeps signing crl existing key number 0. if have renewed new key have 2 distinct crls: ca.crl signed old key , ca(1).crl signed new key. unchanged key have ca.crl although have 2 ca certificates (ca.crt , ca(1).crt)

in case guess right mmc tells (the only) crl file signed sub ca signed ca key not considered trustworthy anymore - per revocation.

you never know how validating apps. handle , app still build chain including old ca certificate. i rather recommend renew again use new key time. (then should have: ca.crl , ca(2).crl, , crt files ca.crt, ca(1).crt, , ca(2).crt).

if hadn't issued certificates since renewal restore backup , re-do renewal without revocation.

generally should not revoke ca because ca had been renewed.

elke





Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client