Partager via


Event ID 66 — AD CS Certificate Revocation List (CRL) Publishing

Applies To: Windows Server 2008

Providing clients with the information that they need to determine whether to trust a certificate is one of the most important security functions of a certification authority (CA) and public key infrastructure (PKI). For the administrator, this means promptly revoking untrusted certificates that have not reached their scheduled expiration dates and publishing this information in certificate revocation lists (CRLs). Monitoring and addressing problems with CRL publication and availability is a critical aspect of PKI security.

Event Details

Product: Windows Operating System
ID: 66
Source: Microsoft-Windows-CertificationAuthority
Version: 6.0
Symbolic Name: MSG_E_DELTA_CRL_PUBLICATION
Message: Active Directory Certificate Services could not publish a delta certificate revocation list (CRL) for key %1 to the following location: %2. %3.%5%6

Resolve

Enable AD CS to publish a certificate revocation list

Possible resolutions to this event log message include:

  • If the event log message specifies an Active Directory location that has been formatted as a Lightweight Directory Access Protocol (LDAP) address, confirm that the certification authority (CA) has Write permissions to this location. To do this, follow the procedure in the "Confirm Active Directory CRL distribution point permissions" section.
  • Check the access control list on any file locations referenced in the event log message to confirm that the CA computer has Write permissions to those locations. To do this, follow the procedure in the "Confirm CRL distribution point permissions" section.
  • Follow the procedure in the "Check network connectivity" section to check network connectivity between the CA and domain controller.
  • After any network or permissions problems have been resolved, use the procedure in the "Publish a new CRL" section to publish a new CRL.
  • If you still cannot publish a new CRL, confirm that the CRL distribution point is valid by following the procedure in the "Confirm the validity of configured CRL distribution points" section.

To perform these procedures, you must have Manage CA permission, or you must have been delegated the appropriate authority.

Confirm Active Directory CRL distribution point permissions

To confirm Active Directory CRL distribution point permissions:

  1. On a computer that has Active Directory management tools installed, click Start, point to Administrative Tools, and click Active Directory Sites and Services.
  2. On the View menu, click Show Services Node.
  3. Double-click Services, and double-click Public Key Services.
  4. Right-click AIA, and click Properties.
  5. Click the Security tab, and confirm that the CA has Write permission to this location.

Confirm file location CRL distribution point permissions

To confirm file location CRL distribution point permissions:

  1. Click Start, type the file share address that you are using to publish CRLs and press ENTER.
  2. Right-click the file share, and click Properties.
  3. Click the Security tab, and confirm that the CA has Write permission to this location.

Check network connectivity

To determine if there is a network connectivity problem between the CA and the domain controller:

  1. Open a command prompt window on the computer hosting the CA.

  2. Type ping <server_FQDN> and press ENTER, where server_FQDN is the fully qualified domain name (FQDN) of the domain controller. If you can connect to the domain controller, you will receive a reply similar to the following:

    Reply from IP_address: bytes=32 time=3ms TTL=59

    Reply from IP_address: bytes=32 time=20ms TTL=59

    Reply from IP_address: bytes=32 time=3ms TTL=59

    Reply from IP_address: bytes=32 time=6ms TTL=59 3.

  3. At the command prompt, type ping <IP_address>, where <IP_address> is the IP address of the domain controller, and then press ENTER.

  4. If you can successfully connect to the domain controller by IP address but not by FQDN, this indicates a possible issue with Domain Name System (DNS) host name resolution.

  5. If you cannot successfully connect to the domain controller by IP address, this indicates a possible issue with network connectivity. Check for and resolve any hardware problems, such as a malfunctioning network card or disconnected network cable, as well as any event log errors relating to firewall configuration Internet Protocol security (IPsec) configuration.

Publish a new CRL

To publish a new CRL by using the Certification Authority snap-in:

  1. Click Start, point to Administrative Tools, and click Certification Authority.
  2. Right-click Revoked Certificates, point to All Tasks, and then click Publish to publish the new CRL.

To publish a new CRL by using the Certutil command-line tool:

  1. Open a command prompt window.
  2. To publish CRLs to all configured CRL publishing locations, type certutil -CRL and press ENTER.
  3. To publish a CRL directly to an Active Directory location, type certutil -dspublish "<crlname.crl>" ldap:///CN=<CA name>,CN=<CA hostname>,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=<contoso>,DC=<com>?certificateRevocationList?base?objectClass=cRLDistributionPoint and press ENTER.

Replace crlname.crl with the name of your CRL file, CA name and CA hostname with your CA name and the name of the host on which that CA runs, and contoso and com with the namespace of your Active Directory domain.

Confirm the validity of configured CRL distribution points

To confirm the validity of configured CRL distribution points:

  1. Click Start, point to Administrative Tools, and click Certification Authority.
  2. Right-click the name of the CA, and click Properties.
  3. Click the Extensions tab. Note the CRL distribution point locations for which the Publish CRLs to this location check box is selected.

You can also determine the configured CRL distribution point URLs by opening a command prompt window on the CA and running the following command: certutil -getreg ca\crlpublicationurls.

Verify

To perform this procedure, you must have Manage CA permission, or you must have been delegated the appropriate authority.

To confirm that certificate revocation list (CRL) publishing is working properly, perform the following procedure on a recently issued end-entity (user or computer) certificate:

  1. Open a command prompt window on a computer that is connected to the network.

  2. Type certutil -url <cert.cer> and press ENTER.

    Replace <cert.cer> with the name of a certificate file that you created by exporting a certificate using the Certificate Export Wizard.

  3. In the dialog box that appears, under Retrieve, click CRLs (from CDP), and click Retrieve.

  4. Confirm that the status of all retrieved CRL distribution points is listed as Verified.

AD CS Certificate Revocation List (CRL) Publishing

Active Directory Certificate Services