Local CRL location of a revoked SubCA-Certificate

Fabian 261 Reputation points
2021-07-08T06:51:14.3+00:00

Hi again ;-)

I was wondering why on a client in the Certificate Manager is an "Intermediate CA\Certificate Revocation List" container, which contains the revoked certificates issued by my Sub CA, but no "Root CA\Certificate Revocation List" container, which would contain the revoked certificates issued by my Root CA? The Endpoint Certificates as well as the SubCA Certificate have some CDP entries. Where is the CRL localy located if I would revoke the certificate of my SubCA?

Best regards, fabian

Windows for business | Windows Server | User experience | Other
{count} votes

Accepted answer
  1. Anonymous
    2021-07-09T02:23:05.87+00:00

    Hello @Fabian ,

    Thank you for posting here.

    I was wondering why on a client in the Certificate Manager is an "Intermediate CA\Certificate Revocation List" container, which contains the revoked certificates issued by my Sub CA, but no "Root CA\Certificate Revocation List" container, which would contain the revoked certificates issued by my Root CA?

    A1: In my test lab (two-tier PKI), I can see there is "Root CA\Certificate Revocation List" container only on my sub CA server.

    For example:
    113122-re.png

    There is "Intermediate CA\Certificate Revocation List" container but no "Root CA\Certificate Revocation List" container on the other machines (domain clients, root CA, and member servers) .

    113087-re1.png

    The Endpoint Certificates as well as the SubCA Certificate have some CDP entries. Where is the CRL localy located if I would revoke the certificate of my SubCA?
    A2:
    C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData

    Here is a similar thread for your reference.

    CRL Cache in Win Server
    https://social.technet.microsoft.com/Forums/ie/en-US/e5144995-5fda-4ffb-be4e-eb6c578c63b6/crl-cache-in-win-server?forum=winserversecurity

    Hope the information above is helpful.

    Should you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


1 additional answer

Sort by: Most helpful
  1. Anonymous
    2021-07-12T09:32:03.327+00:00

    Hello @Fabian ,

    I am sorry for the late reply. Thank you for your update.

    Here are the answers for your references.

    What is the Revocation List container used for if there is a local cache?
    A1: I think the function of Revocation List container is the same as local cache.
    Local cache is the store location of CRL files. And Revocation List container is UI display information.

    Why is the Revocation List Container structure of the SubCA different from other computers?
    A2: I think it is by design. I am sorry, I do not know why.

    Hope the information above is helpful.

    Should you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.