I am facing so many errors even i had renewed the CRL:-
Pls see the below command output:-
C:\>certutil -verify -urlfetch subca.cer
Issuer:
CN=RootCA
Name Hash(sha1): f92d4c38e5d39ffde4a765f2beb33649a3251b40
Name Hash(md5): 916ea49232fe1e7d9a55a2b0fc3bea07
Subject:
CN=IssuingCA
DC=
DC=com
Name Hash(sha1): 092621f67eda752ac6b135cd04d0b401fa060080
Name Hash(md5): b0b67c26fec73affd607fc0ec12655fd
Cert Serial Number: 1400000005173179d78d8fd3db000000000005
dwFlags = CA_VERIFY_FLAGS_CONSOLE_TRACE (0x20000000)
dwFlags = CA_VERIFY_FLAGS_DUMP_CHAIN (0x40000000)
ChainFlags = CERT_CHAIN_REVOCATION_CHECK_CHAIN_EXCLUDE_ROOT (0x40000000)
HCCE_LOCAL_MACHINE
CERT_CHAIN_POLICY_BASE
-------- CERT_CHAIN_CONTEXT --------
ChainContext.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
ChainContext.dwErrorStatus = CERT_TRUST_REVOCATION_STATUS_UNKNOWN (0x40)
ChainContext.dwErrorStatus = CERT_TRUST_IS_OFFLINE_REVOCATION (0x1000000)
ChainContext.dwRevocationFreshnessTime: 208 Days, 17 Hours, 51 Minutes, 14 Secon
ds
SimpleChain.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
SimpleChain.dwErrorStatus = CERT_TRUST_REVOCATION_STATUS_UNKNOWN (0x40)
SimpleChain.dwErrorStatus = CERT_TRUST_IS_OFFLINE_REVOCATION (0x1000000)
SimpleChain.dwRevocationFreshnessTime: 208 Days, 17 Hours, 51 Minutes, 14 Second
s
CertContext[0][0]: dwInfoStatus=102 dwErrorStatus=1000040
Issuer: CN=RootCA
NotBefore: 9/18/2014 6:59 AM
NotAfter: 9/18/2024 7:09 AM
Subject: CN=IssuingCA, DC=, DC=com
Serial: 1400000005173179d78d8fd3db000000000005
Template: SubCA
b3556525827fe8477b5503fd779278c9dd3ce39f
Element.dwInfoStatus = CERT_TRUST_HAS_KEY_MATCH_ISSUER (0x2)
Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
Element.dwErrorStatus = CERT_TRUST_REVOCATION_STATUS_UNKNOWN (0x40)
Element.dwErrorStatus = CERT_TRUST_IS_OFFLINE_REVOCATION (0x1000000)
---------------- Certificate AIA ----------------
Failed "AIA" Time: 0
Error retrieving URL: The request is not supported. 0x80070032 (WIN32: 50 ER
ROR_NOT_SUPPORTED)
file:////rootca01/CertEnroll/rootca01_RootCA.crt
Failed "AIA" Time: 0
Error retrieving URL: The server name or address could not be resolved 0x800
72ee7 (INet: 12007 ERROR_INTERNET_NAME_NOT_RESOLVED)
http://subca01.domain.com/CertEnrollrootca01_RootCA.crt
---------------- Certificate CDP ----------------
Failed "CDP" Time: 0
Error retrieving URL: Forbidden (403). 0x80190193 (-2145844845 HTTP_E_STATUS
_FORBIDDEN)
http://subca01/pki/RootCA.crl
---------------- Base CRL CDP ----------------
No URLs "None" Time: 0
---------------- Certificate OCSP ----------------
No URLs "None" Time: 0
--------------------------------
CRL 05:
Issuer: CN=RootCA
ThisUpdate: 9/18/2014 1:36 AM
NextUpdate: 3/19/2015 1:56 PM
0ad36833c693909fdd17c03903ac100eafe33111
Issuance[0] = 1.2.3.4.1455.67.89.5
CertContext[0][1]: dwInfoStatus=10c dwErrorStatus=0
Issuer: CN=RootCA
NotBefore: 9/15/2014 8:46 AM
NotAfter: 9/15/2034 8:56 AM
Subject: CN=RootCA
Serial: 16643f83b5fe09bb4f2e6ff45e5b0eda
5209f7a05de8a03dc000a3730d1d75c547e19911
Element.dwInfoStatus = CERT_TRUST_HAS_NAME_MATCH_ISSUER (0x4)
Element.dwInfoStatus = CERT_TRUST_IS_SELF_SIGNED (0x8)
Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
---------------- Certificate AIA ----------------
No URLs "None" Time: 0
---------------- Certificate CDP ----------------
No URLs "None" Time: 0
---------------- Certificate OCSP ----------------
No URLs "None" Time: 0
--------------------------------
Issuance[0] = 1.2.3.4.1455.67.89.5
Exclude leaf cert:
0f01f716b3f1650c84e26216b2a79c0ce12e4be9
Full chain:
570d3f37fa78953bce487538c839c5acc4ab7309
Issuer: CN=RootCA
NotBefore: 9/18/2014 6:59 AM
NotAfter: 9/18/2024 7:09 AM
Subject: CN=IssuingCA, DC=, DC=com
Serial: 1400000005173179d78d8fd3db000000000005
Template: SubCA
b3556525827fe8477b5503fd779278c9dd3ce39f
The revocation function was unable to check revocation because the revocation se
rver was offline. 0x80092013 (-2146885613 CRYPT_E_REVOCATION_OFFLINE)
------------------------------------
Revocation check skipped -- server offline
Cert is a CA certificate
ERROR: Verifying leaf certificate revocation status returned The revocation func
tion was unable to check revocation because the revocation server was offline. 0
x80092013 (-2146885613 CRYPT_E_REVOCATION_OFFLINE)
CertUtil: The revocation function was unable to check revocation because the rev
ocation server was offline.
CertUtil: -verify command completed successfully.