In Windows Explorer on the root CA, locate the certificate revocation list you just published. The CRL's default location is:%systemroot%\system32\CertSrv\CertEnroll\<CAname>.crl. Right-click the CRL file and send it to a drive that has portable storage media.
↑ Return to Top
There are several considerations related to building an offline root CA. The following sections link to additional information related to PKI design, offline root CA installation, and frequently asked questions (FAQ).
Ed Price - MSFT edited Revision 24. Comment: Added whitespace below TOC. Added tags
Ed Price - MSFT edited Revision 23. Comment: Added whitespace between lines. Added tags.
Kurt L Hudson edited Revision 19. Comment: Added return to top links
Kurt L Hudson edited Revision 16. Comment: Removed the "should have IIS installed" totally not needed anymore
Douks edited Revision 14. Comment: Added a link to Vadim's useful article on Root CA Certificate Renewal.
Ed Price - MSFT edited Revision 12. Comment: Fixed TOC issues.
Kurt L Hudson edited Revision 10. Comment: Updated formatting and some titles
Kurt L Hudson edited Revision 9. Comment: Finished update of tables
Kurt L Hudson edited Revision 8. Comment: Work in progress saving table now.
Kurt L Hudson edited Revision 7. Comment: Mid-update trying to replace a TechNet document checklist by adding it here
Kurt L Hudson edited Original. Comment: Fixed the title
Kurt L Hudson edited Revision 1. Comment: Added more design resources
Kurt L Hudson edited Revision 2. Comment: Added some punctuation and clarification
Kurt L Hudson edited Revision 3. Comment: Added information about how to apply Windows Updates to offline CAs
Kurt L Hudson edited Revision 4. Comment: fixed typos and corrected upper/lowercase issues
Kurt L Hudson edited Revision 5. Comment: Added link to PKI Design Brief Overview
Very good ! :)
Thanks. Also, great links...
Kurt L Hudson edited Revision 16. Comment: Removed