How to fix the mismatch of CRL Link in CSR and IIS server certificate

Dilip Patel, Vipul (Cognizant) 0 Reputation points
2024-05-17T14:43:22.27+00:00

Hi Team,

We have a CSR generated for 1 of the servers but while user are accessing the server via RDP they get an error as the CRL check is failing.

Upon checking the issue we could find that the CRL URL link is missmatched in CSR certificate and IIS server.

Can we change the CRL URL link in CA admin console to resolve the issue or do we have any other way around.

Thank you

Microsoft Office Online Server
Microsoft Office Online Server
Microsoft on-premises server product that runs Office Online. Previously known as Office Web Apps Server.
611 questions
Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,356 questions
Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,330 questions
Not Monitored
Not Monitored
Tag not monitored by Microsoft.
37,262 questions
Microsoft Managed Desktop
Microsoft Managed Desktop
A cloud-based service that brings together Microsoft 365 Enterprise and adds these features: User device deployment; IT service management and operations; and Security monitoring and response.
46 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Miguel Gonçalves | AVANADE 886 Reputation points
    2024-06-14T22:11:02.12+00:00

    HI Dilip Patel, Vipul (Cognizant)

    After Check the CRL Distribution Point download the CRL on the server. This link https://techcommunity.microsoft.com/t5/iis-support-blog/crl-checking-by-iis/ba-p/348170will be pointing to one of the CDP servers hosted by the CA. Verify CRL and define your CertCheckMode (above link detail). Restart IIS. If needed you can clear CRL cache https://stackoverflow.com/questions/75360269/how-to-disable-certificate-revocation-list-crl-caching-on-iis-10-0

    # If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    0 comments No comments