Menu
InformatiWeb Pro
  • Index
  • System admin
  • Virtualization

Login

Registration Password lost ?
FR
  • Windows Server
    • WMS 2012
    • WS2012 R2
    • WS2016
  • Citrix
    • Citrix NetScaler Gateway
    • Citrix XenApp / XenDesktop
    • Citrix XenServer
  • VMware
    • VMware ESXi
    • VMware vSphere
    • VMware Workstation
  • Microsoft
    • Hyper-V
  • RAID
    • Adaptec SmartRAID
  • UPS
    • APC Back-UPS Pro
  • InformatiWeb Pro
  • System admin
  • Windows Server
  • Courses
  • Learn how to use Active Directory Certificate Services (AD CS) on WS 2016
  • How revocation works and publishing a CRL ?
13 / 21
  • Export or import a certificate
  • Publish CRLs accessible via the web (HTTP)

How revocation works, why use it and publish a revocation list (CRL) ?

  • Windows Server
  • 03 November 2023 at 09:52 UTC
  • InformatiWeb
  • 2/2
Previous page

7. Publish a delta revocation list (delta CRL)

To avoid that your clients have to re-download the full revocation list (CRL) each time or to make the revocation detected faster (since delta CRLs are published more frequently, by default), you have the option to publish manually a delta revocation list (delta CRL) instead of a full revocation list (CRL).

7.1. Using a new certificate

For this tutorial, we issued a new certificate to our web server.
This new certificate is therefore valid.

Here is the serial number of this new certificate.

7.2. Revoke certificate

To revoke the certificate, open the "Certification Authority" console and go to the "Issued Certificates" section.

If necessary, double-click the desired certificate to ensure that it's the correct certificate to revoke.

To be sure, you can look at its serial number.

Revoke this certificate by right-clicking "All Tasks -> Revoke Certificate" on it.

Choose the reason you want to specify for the revocation of this certificate, as well as the date from which this revocation should take effect.
Default, now.

The revoked certificate disappears from the list of issued certificates.

The revoked certificate appears in the list of revoked certificates.

7.3. Publish delta revocation list (delta CRL)

To let your servers and client workstations know that this certificate has been revoked, you must publish its serial number in a revocation list (CRL) or a delta revocation list (delta CRL).

To do this, right-click "All Tasks -> Publish" on the "Revoked Certificates" folder.

This time, we will publish a delta revocation list (delta CRL).
To do this, select "Delta CRL only" and click OK.

To verify that the publication has taken place, right-click on the "Revoked Certificates" folder.
Then, in the "View CRL" tab, click the "View CRL" button (at the bottom of the window).

In the "Certificate Revocation List" window that appears, go to the "Revocation List" tab.

The serial number of the certificate you just revoked appears in the list of revoked certificates in this certificate revocation list.

As expected, on the client side, access to the protected service with this revoked certificate will be blocked.

On some client workstations, it's again possible that access is still possible despite the associated certificate having been revoked in the meantime.

If so, clear your web browser's cache.

Then, empty the revocation cache of your client workstation by running the command below.

Batch

certutil -setreg chain\ChainCacheResyncFiletime @now

Now, access to the associated service will be blocked and the error "This organization certificate has been revoked" will appear.

Share this tutorial

Partager
Tweet

To see also

  • SafeNet Authentication Client (SAC) - Installation and overview

    Articles 1/26/2024

    SafeNet Authentication Client (SAC) - Installation and overview

  • What is encryption and how does it work ?

    Articles 9/8/2023

    What is encryption and how does it work ?

  • WS 2016 - AD CS - Backup and restore a certificate authority (CA)

    Windows Server 12/29/2023

    WS 2016 - AD CS - Backup and restore a certificate authority (CA)

  • WS 2016 - AD CS - Buy smart cards and log in via them

    Windows Server 1/19/2024

    WS 2016 - AD CS - Buy smart cards and log in via them

Comments

No comment

Share your opinion

Pinned content

  • Software (System admin)
  • Linux softwares
  • Our programs
  • Terms and conditions
  • Share your opinion

Contact

  • Guest book
  • Technical support
  • Contact

® InformatiWeb-Pro.net - InformatiWeb.net 2008-2022 - © Lionel Eppe - All rights reserved.

Total or partial reproduction of this site is prohibited and constitutes an infringement punishable by articles L.335-2 and following of the intellectual property Code.