CDP Location keeps expiring

Anonymous
2020-07-15T06:54:12.543+00:00

I would like some info on a very specific CA behaviour that I won't find any information on web.
We have this PKI, with a RootCA that would be turned off followed by two subordinates.
Currently everything seems to working fine, as long as I keep my RootCA online. CDP Location keeps expiring, but in the day of expiration it will renew to the next 3 days, and keep doing so. If I turn off the RootCA, I will need to turn it on again to renew.
On the top of root CA on the Enterprise PKI management tool, I noticed that the both CDP Locations (#1, #2) are set to expire in July this year, and locations are not the same as in the subordinates, so probably some sort of misconfiguration on pointing the CDP?
As show in Root CA:
12279-ma1.png

As show in SubCAs:
12280-ma2.png

No issues on CA Certificate and AIA Location.
Did everyone ever face this specific issue on CA?
Thanks in advance.

Source link:
https://social.technet.microsoft.com/Forums/windowsserver/en-US/cb0a19be-e219-4303-9e38-b630b27cfe99/cdp-location-keeps-expiring?forum=winserverManagement

Windows for business Windows Server User experience Other
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2020-07-15T07:06:17.45+00:00

    Hello,
    Thank you for posting here!

    Here are the asnwers for our questions:

    Q1: CDP Location keeps expiring, but in the day of expiration it will renew to the next 3 days, and keep doing so. If I turn off the RootCA, I will need to turn it on again to renew.

    A1: Do we mean the CDP Location #1 on Enterprise CA1?
    If so, we can check if the CRL publications interval is three days. If so, we can change it.
    12390-18.png
    And we can check Effective date and Next update about the CRL file.
    12451-20.png

    Usually, the CDP Locations will update automatically. But if it is expired, we should republish it manually.
    12452-21.png
    Q2: On the top of root CA on the Enterprise PKI management tool, I noticed that the both CDP Locations (#1, #2) are set to expire in July this year, and locations are not the same as in the subordinates, so probably some sort of misconfiguration on pointing the CDP?

    A2: If there is no error in PKIview.msc, I mean the status is OK, then the PKI is healthy.

    In my lab, CDPs about root CA and sub CA are not the same. It is normal.
    12433-22.png

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.