Hi,
I am a bit confused by the variety of ways to publish offline root CA to AD
found on the web. I am interesting in publishing .CRT and .CRL manually to AD
with the help of CERTUTIL tool (something that should be done manually every
6 month for CRLs). Can anyone please confirm that the following way of doing
it is correct?
To publish root CA certificate:
certutil –dspublish –f <RootCertificate_filename.crt> <NameOfRootCA>
To publish root CA CRL:
Certutil –dspublish –f <RootCRL_filename.crl> <? Probably name of Root CA
again, but I’m not sure>
What records should normally appear in AD under “AD Sites and Services >
Services > Public Key Services>” after issuing above commands correctly.
Thank you very much for your help,
Regards,
Alex
>> Stay informed about: Publishing CA