Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Enterprise PKI and AD CS cannot download/get revocation list for offline root CA

$
0
0

I have everything configured correctly for AIA and CDP locations, as you can see here:



..but it keeps saying "Unable To Download" and without a flag set for revocation checks to be ignored, everytime I try to start my Subordinate CA it says "E_CRYPT_REVOCATION_OFFLINE" or something like that.

The IIS server is the same server as the Subordinate CA, sharing the PKI folder with everyone as you can see in the locations. If I go the URL for CDP Location #1 on any server (including this one), it downloads the CRL fine, so I don't know why it's saying it can't

I will appreciate any help and insight. :) if you need more info please ask.


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>