Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

(SOLVED) AD CS: Offline Root CA and Subordinate CA - CRYPT_E_REVOCATION_OFFLINE

$
0
0

I followed this guide: https://www.vkernel.ro/blog/how-to-publish-the-crl-and-aia-on-a-separate-web-server to properly configure my CRL locations for IIS. Thank you guys :)

----------------

Like the title states, I have an offline, standalone Root CA Windows Server 2019 instance and I used it to issue a certificate for my subordinate CA. I have done the following:

Yet every time I try to start the Sub CA, it throws this error: "CRYPT_E_REVOCATION_OFFLINE"

I'm getting past this error for now by setting the registry to ignore that error:

certutil –setreg ca\CRLFlags +CRLF_REVCHECK_IGNORE_OFFLINE

..but ideally I want my clients to check the Root CA's CRL to ensure the Sub CA is valid.

What else can I do here?



Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>