CDP Location keeps expiring

Daisy Zhou 18,721 Reputation points Microsoft Vendor
2020-07-15T06:54:12.543+00:00

I would like some info on a very specific CA behaviour that I won't find any information on web.
We have this PKI, with a RootCA that would be turned off followed by two subordinates.
Currently everything seems to working fine, as long as I keep my RootCA online. CDP Location keeps expiring, but in the day of expiration it will renew to the next 3 days, and keep doing so. If I turn off the RootCA, I will need to turn it on again to renew.
On the top of root CA on the Enterprise PKI management tool, I noticed that the both CDP Locations (#1, #2) are set to expire in July this year, and locations are not the same as in the subordinates, so probably some sort of misconfiguration on pointing the CDP?
As show in Root CA:
12279-ma1.png

As show in SubCAs:
12280-ma2.png

No issues on CA Certificate and AIA Location.
Did everyone ever face this specific issue on CA?
Thanks in advance.

Source link:
https://social.technet.microsoft.com/Forums/windowsserver/en-US/cb0a19be-e219-4303-9e38-b630b27cfe99/cdp-location-keeps-expiring?forum=winserverManagement

Windows Server Management
Windows Server Management
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Management: The act or process of organizing, handling, directing or controlling something.
422 questions
0 comments No comments
{count} votes

Accepted answer
  1. Fan Fan 15,301 Reputation points Microsoft Vendor
    2020-07-15T07:06:17.45+00:00

    Hello,
    Thank you for posting here!

    Here are the asnwers for our questions:

    Q1: CDP Location keeps expiring, but in the day of expiration it will renew to the next 3 days, and keep doing so. If I turn off the RootCA, I will need to turn it on again to renew.

    A1: Do we mean the CDP Location #1 on Enterprise CA1?
    If so, we can check if the CRL publications interval is three days. If so, we can change it.
    12390-18.png
    And we can check Effective date and Next update about the CRL file.
    12451-20.png

    Usually, the CDP Locations will update automatically. But if it is expired, we should republish it manually.
    12452-21.png
    Q2: On the top of root CA on the Enterprise PKI management tool, I noticed that the both CDP Locations (#1, #2) are set to expire in July this year, and locations are not the same as in the subordinates, so probably some sort of misconfiguration on pointing the CDP?

    A2: If there is no error in PKIview.msc, I mean the status is OK, then the PKI is healthy.

    In my lab, CDPs about root CA and sub CA are not the same. It is normal.
    12433-22.png

    0 comments No comments

0 additional answers

Sort by: Most helpful