Updating out of date, ADCS certificate revocation list

james gledson 0 Reputation points
2024-02-05T21:53:26.5833333+00:00

If the CRL on an internal Active Directory CA has been out of date for sometime. Will there be any issues if an up to date CRL is published. What would be the safest way to go about updating the CRL Thanks.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,880 questions
Windows Server Management
Windows Server Management
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Management: The act or process of organizing, handling, directing or controlling something.
421 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,586 Reputation points
    2024-02-05T22:51:21.1066667+00:00

    Hi You can update CRL without any issues. It’s important to keep it up to date to let clients able to identify revoked certificates. It is recommended to keep CRL up to date automatically.

    Please don’t forget to accept helpful answer

    0 comments No comments

  2. Daisy Zhou 18,706 Reputation points Microsoft Vendor
    2024-02-06T02:01:21+00:00

    Hello james gledson,

    Thank you for posting in Q&A forum.
    *
    If the CRL on an internal Active Directory CA has been out of date for sometime. Will there be any issues if an up to date CRL is published.* A: If there is any certificate is revoked during this time, then after you update the CRL to the newest file, and if this certificate can access the newest CRL file and Delta CRL file when it is used, then this certificate may not be used (because it checks that this certificate is revoked).

    If there is no any certificate is revoked during this time, then there will be no impact. What would be the safest way to go about updating the CRL.
    A:
    You can right click Revoked Certificate container and select Publish\All Tasks and select New CRL\Click OK.*
    *
    And right click Revoked Certificate container and select Publish\All Tasks and select Delta CRL only\Click OK.Windows Certificate Services - Setting up a CRL | PeteNetLive

    Or you can publish CRL with command:
    Certutil -config "CAMchineName\CAName" -CRL Certutil -config "CAMchineName\CAName" -CRL delta

    For example: User's image

    I hope the information above is helpful. If you have any questions or concerns, please feel free to let us know. Best Regards, Daisy Zhou

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments