Yeah it's a 3 weeks old installation.
No certificates for clients or users have this issue, as this certificates were issued from the sub ca with the correct crl and crt locations.
Is there any i've to do with existing certificates for clients and users when using the "reuse key option"?
What i not understand is when i now execute this steps on the sub ca (renew certificate with reuse key option) how does the sub ca recognize the new crl paths which i've configured on the offline root ca ... as there seems to be no connection?!?
Could you please explain step by step what do execute were? Thanks a lot guy!!!!!
mero
Main Topics
Browse All Topics





by: ParanormasticPosted on 2009-04-14 at 11:12:48ID: 24140960
You need to renew the sub CA's certificate for the new CDP from the root to propagate. This is not a dynamic process. You will also note that any of the certs issued from the sub CA to users/devices before updating that will have the same issue.
om/en-us/l ibrary/cc9 62077.aspx
You can make things a little easier on yourself by reusing the same keyset since I'm assuming this is a pretty new CA installation if you have this kind of issue.
Here's the general instructions - since your root is offline you will need to just go about that the same way you did when you set up the sub CA in the first place (copy the csr file to the root).
http://technet.microsoft.c