CRL does not automatically renew under Windows

Posted on 2009-04-15
Last Modified: 2012-05-06
One of my sites is behind a proxy server. At that site, some computers (a couple of XP machines, a Vista laptop, and now our new Server 2008) do not update their Verisign CRLs. These machines are not on a domain. I have been unable to find any information on how this mechanism works, or how to trigger it manually. Other machines at the site seem to be fine.

This is a major issue for us, because we use Patchlink over https. When that CRL becomes invalid, Patchlink stops working until I manually import the certificate by downloading it from Verisign and installing it by hand. Anyone have any ideas?

Question by:yunbukogar
  • 4
  • 3
LVL 31

Expert Comment

ID: 24150282
This should be an automatic process.  The CRL has a 'next update' tag within it, instructing the client when they should start looking for the next CRL.  If this is not being downloaded automatically, I would suspect that your firewall is blocking the traffic.  Typically the CRL will be pushed over http (TCP port 80).

Author Comment

ID: 24151945
Hi Paranormastic, I was thinking the same thing. What I can't figure out is why some work, but some don't. I also don't know what server the serves the CRL. Anyone have any idea or some idea how to find out? Is it as simple as 
LVL 31

Expert Comment

ID: 24152490
Assuming its the same as the one for the cert they use on their own site, it would be:

You can look at your certificate's properties and on the Details tab look for CRL Distribution Point (CDP) attribute and select that.  In the box in the bottom half it will show where the CDP location(s) are.

You can also try: internet options - content tab - Clear SSL State

Can also try clearing temp internet files, history, etc. and if there is a proxy to clear that out - maybe some servers are set to use a proxy and some aren't and the proxy is serving a stale copy of the CRL.
LVL 31

Expert Comment

ID: 24152503
Even if your hardware firewall is set up correctly, don't forget about any software firewalls that you might have installed, too ;)
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.


Expert Comment

ID: 24153230
Hi Ken,
Can the infected computers reach the internet? Is this problem located to only computers not joined to the domain? If so it could your proxy settings are not configured correctly on the affected machines.

Also, opening the local computer certificate store through the mmc -> certificates, in the details fan, you shold be able to see the CRL distribution points. Try copy/paste the URL's into Iexplorer and see if you get a download CRL prompt...or perhaps an error indicating the issue.


Author Comment

ID: 24297967
Hi guys,

If I download the CRL manually, it works fine. I do have to install it by hand into the physical store, but it works until it expires again. AFAIK, the proxy is correct (or at least the same on computers that have the problem and computers that don't.)

Author Comment

ID: 24299023
Hi Greenhelmet,

I'm looking at the mmc/certificates now, and I have the CRL. I don't see any CRL distribution points listed, but if I go to the website of my server, I can get the CDP there.

Looking at the cert in the mmc, it says the next update is Wednesday, April 29, 2009, 12:15:29 PM, exactly 2 weeks since I last installed it.

I'm thinking perhaps it tries to update certs using the localsystem account, which does not have a proxy set up for it. Is there any way to set that up--or set it up for the account it does use?

Accepted Solution

yunbukogar earned 0 total points
ID: 24496114
OK, I've fixed it--I had to use net winhttp set proxy yadda yadda. Apparently the CRL function operates under winhttp, not under the IE proxy settings.

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Can I legally transfer my OEM version of Windows to another PC?  (AKA - Can I put a new systemboard in my OEM PC?) Few of us are both IT and legal experts but we all have our own views of Microsoft's licensing rules and how they apply.  There are…
Scenario:  You do full backups to a internal hard drive in either product (SBS or Server 2008).  All goes well for a very long time.  One day, backups begin to fail with a message that the disk is full.  Your disk contains many, many more backups th…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now