CA Cannot Publish CRLs to the Active Directory After the First Certificate Expires (289622)



The information in this article applies to:

  • Microsoft Windows 2000 Server SP1
  • Microsoft Windows 2000 Advanced Server SP1
  • Microsoft Windows 2000 Professional SP1

This article was previously published under Q289622

SYMPTOMS

When the first certificate issued by a Certificate Authority (CA) expires and the CA chooses to renew its certificates by using the original key pairs, the CA may not be able to publish certificate revocation lists (CRLs) to the Active Directory.

CAUSE

STATUS

Microsoft has confirmed that this is a problem in Microsoft Windows 2000.

Microsoft is researching this problem and will post more information in this article when the information becomes available.

Modification Type:MajorLast Reviewed:11/19/2003
Keywords:kbbug kbfix kbpolicy KB289622