How to check on CRL of old CA keypair after renewal with new keypair

Dieter Grasser 41 Reputation points
2021-03-24T14:05:08.007+00:00

Hi All,

I renewed our Issuing CAs certificates with new keys.

That work kinda fine and I think it should be alright. I still need to fix OCSP but that should be alright.

However, I am kinda confused by the way pkiview shows the current health of the CA.

I still have plenty of certificates signed with the old keypair and will continue to have for some time. Consequently, I'd like to check on CRL publishing status for the old keypair.

However, pkiview only shows the CRL/AIA/CRL+ for the new keypair.

81189-grafik.png

Is there a way to make pkiview show also the CRL status etc for the old keypair (would be handy, as some of the certificates will be valid for another 18month)

Cheers,
R

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,717 questions
{count} votes

Accepted answer
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2021-03-25T01:43:17.337+00:00

    Hi,

    We can't make pkiview show both the CRL status.

    Before the old CA certificates expires , just don't delete the old ones.
    The CRL of old CA keypair after renewal with new keypair, still existed in the CertEnroll folder on both the CA and the web server, as following:
    81288-3251.jpg
    81249-3252.jpg

    For how the crl (old and new ) checked by the clients when Renewal with new key pair, you can refer to the following link:
    https://social.technet.microsoft.com/wiki/contents/articles/2016.root-ca-certificate-renewal.aspx
    https://www.experts-exchange.com/articles/32336/CA-Validity-Period-Extension-and-CA-Certificate-Renewal-Process.html

    This response contains a third-party link. We provide this link for easy reference. Microsoft cannot guarantee the validity of any information and content in this link.
    Best Regards,

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Dieter Grasser 41 Reputation points
    2021-04-07T11:15:08.627+00:00

    Hey,

    sorry for the late reply and thank you for your answer.

    I would have liked to have an overall view in pkiview or sth. My CA will continue to publish CRLs for almost 2 year and this reduces the utility of pkiview greatly in my opinion. So far, I checked pkiview and knew on first glance if everything was in order. Now, I have to check the publishing points manually, if I understand correctly.

    I just tested and if I delete the current CRL and CRL(+), which were created with the old keypair, pkiview claims that everything is fine. However, the old certificates will be regarded as invalid, cause the CRL is missing.

    Kind regards,
    R

    0 comments No comments