Certificates not using following Active Directory Certificate Services settings

Mark Davies 0 Reputation points
2024-10-14T20:40:50.63+00:00

I've setup Active Directory Certificate Services and set the CRL Publication Interval to daily and the Delta publication interval to 30 minutes. Then within the Online Responder setup, this is set to 15 minutes.

However, when I then check an exported certificate with certutil -f -urlfetch -verify the none of the times match with what is set.

User's image

User's image

User's image

I'm not sure if I've missed a setting or something which may be causing this.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Yanhong Liu 14,285 Reputation points Microsoft External Staff
    2024-10-16T06:06:17.3533333+00:00

    Hello

    Thank you for posting in Q&A forum.

    The first image shows when the CRL will be updated.

    While this command shows which certificates are verifiable and valid, you should compare this certificate with the CRL.

    Basic CRL checking with certutil - Microsoft Community Hub

    Best regards

    Yanhong

    =====================================

    If the answer is helpful, please click "Accept answer" and upvote it

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.