question

NSC-8481 avatar image
0 Votes"
NSC-8481 asked LimitlessTechnology-2700 answered

adcs offline root ca has crl errors "unable to download"

Have Microsoft pki running for 2 years SCCM relies upon it at this point as well as the CMG and Intune. The ca servers are all 2019 as well is AD schema and forest functional level. We have one roots CA off domain and offline and one subca on the domain. Have a webserver in our dmz and I am trying to publish the crl there for Windows Hello clients. How do I update the rootca CRl and get it to the webserver? I have red x on the CDP and AIA locations in pkiveiw for the the http extensions of both and I cant seem to change. Am I screwed ? Do I have to build again?

Thanks for any help

windows-active-directory
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

LimitlessTechnology-2700 avatar image
0 Votes"
LimitlessTechnology-2700 answered

Hello NSC-8481,

Thank you for your question.

There is a topic similar to what you are facing, see the link below to check the problem resolution:

https://social.technet.microsoft.com/Forums/windowsserver/en-US/ef8711cc-b325-4abb-bc50-20f86e2741d0/fix-cdp-location-on-offline-root-ca?forum=winserversecurity#53e581ba- ceac-431e-b2c2-0307523bbaf4

If the answer was helpful, please don't forget to vote up or accept as an answer, thanks.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.