Re: How to force CRL update ?

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Dmitry Korolyov [MVP] (d__k_at_removethispart.mail.ru)
Date: 04/20/04


Date: Tue, 20 Apr 2004 17:33:03 +0400

I believe that you can immediately publish complete CRL or a delta CRL using
CA mmc console, from the context menu of CA.

-- 
Dmitry Korolyov [d__k@removethispart.mail.ru]
MVP: Windows Server - Active Directory
  "Martin K." <zanny[spam]@poczta.onet.pl> wrote in message
news:uLehaFrJEHA.644@tk2msftngp13.phx.gbl...
    Hi,
  I have issued some certificates for smatcard logon to Active Directory.
  Certificates have CRL Distribution point extension populated with valid
  data. CRLs are issued every few hours, and every time a certificate is
  revoked or suspended, unfortunately DC seems to cache CRL until CRLs Next
  Update. Is there a possibility to force DC reload new CRL before CRLs Next
  Update ?
    regards
  Martin K.


Relevant Pages

  • Re: Proposal for a new PKI model (At least I hope its new)
    ... it is online and it is dynamic. ... What is your solution in place of PKI and certificates? ... > distributed real-time CRL model. ... absolutely know all possible relying parties ... ...
    (sci.crypt)
  • RE: CLR and AIA publishing properties unclear
    ... enterprise issuing CA and a web server hosting CRL and AIA for external ... include path in certificates. ... I do however publish CRL and deltas, CRL path should be ... should be included in certificates and delta CRL path in CRL's. ...
    (microsoft.public.windows.server.general)
  • CLR and AIA publishing properties unclear
    ... enterprise issuing CA and a web server hosting CRL and AIA for external ... I am however in doubt of a few CRL/AIA publishing properties. ... include path in certificates. ... I do however publish CRL and deltas, CRL path should be ...
    (microsoft.public.windows.server.general)
  • RE: RADIUS IAS CRL CHECK
    ... However, when the workstation is turned on, it can establish a ... It seems that the IAS ignores the CRL. ... certificates' in the DC, we do get an error of "The certificate is ...
    (microsoft.public.internet.radius)
  • Problems with CRL
    ... I issued selfsigned root certificate, then issued user certificates signed ... Before I issued second root new CRL always replaced the old one. ... And when I revoke certificate issued by old root, ...
    (microsoft.public.platformsdk.security)