Why expired certificates are not in revoked folder (2024)

  • Article

Question

Monday, December 16, 2019 12:26 PM

Hello

There are lots of domain computer and user certificates in CA console that are expired but they are not moved to revoked folder. why is that?

Also I need an article to describe what happens to create these computer and user certificates automatically and when we need them.

thanks in advance

All replies (4)

Tuesday, December 17, 2019 3:41 AM ✅Answered

Hello,
Thank you for posting in our TechNet forum.

***Q1:*There are lots of domain computer and user certificates in CA console that are expired but they are not moved to revoked folder. why is that?

**A1:**According to my understanding, revocation and expiration are two different states of a certificate.

The revoked certificate does not necessarily expire. The revocation should be revoked for some reason, so that the end user or the device can no longer use the certificate. Only revoked certificates will be moved to revoked certificates folder.

An expired certificate is just unusable. We can renew the certificate before it expires so that we can continue to use the certificate normally. If we don’t need this certificate anymore, we don’t need to renew this certificate before it expires. When the certificate expires, we can delete the expired certificate.

***Q2:**Also I need an article to describe what happens to create these computer and user certificates automatically and when we need them.
*
A2: do we mean whether we want to set up certificate auto enrollment? If so, when our computers and users are too many, we do not want to enroll certificates manually and we want tomanage certificates in batches., then we can set upcertificate auto enrollment through GPO.

For more information about how to set up certificate auto enrollment, we can refer to the article:
**
Set Up Automatic Certificate Enrollment (Autoenroll)
https://www.vkernel.ro/blog/set-up-automatic-certificate-enrollment-autoenroll

**
Tip: This answer contains the content of a third-party website. Microsoft makes no representations about the content of these websites. We provide this content only for your convenience.

Best Regards,
Daisy Zhou

Please remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact [email protected].

Monday, December 16, 2019 5:53 PM

Why they should be revoked? Expired certificates are just expired. Revoked certificates are different. Revocation process is used to explicitly discontinue the trust to a certificate within its validity period. So it is expected behavior.

Vadims Podāns, aka Crypt32
My weblog: www.sysadmins.lv
PowerShell PKI Module: PSPKI
Check out new: SSL Certificate Verifier
Check out new: ASN.1 Editor tool.

Tuesday, December 17, 2019 12:29 PM

Thank you dear Daisy

your response is exactly my answer and I will mark it as answer, just to avoid creating another post, I have to ask another 2 small question : expired certificates can be used or I have to revoke them? 2- Is it reasonable to delete crl list when it is big? ( according to my understanding if the certificate is revoked then it can not be used so why should I maintain that in the list for long period of time? what is the point? )

Thanks in advance

Wednesday, December 18, 2019 7:42 AM

Hi,
Thank you for your reply.

***Q1: expired certificates can be used or I have to revoke them?

***A1: Expired certificates can not be used by the end entity (such as users or computers).

If the certificates issued by the root CA are expired:

We can deleted these certificates directly from CA and client.

Or we can re-issue these certificates if we still want to use such certificates.**

Q2:Is it reasonable to delete crl list when it is big? ( according to my understanding if the certificate is revoked then it can not be used so why should I maintain that in the list for long period of time? what is the point? )

A2: If the certificate is revoked, it can not be used.

What do we mean crl list? Where is the crl list we mentioned (on the CA or on the Clients) ?

Do we mean the crl list is the crl files in CertEnroll folder as below?**

Why expired certificates are not in revoked folder (1)

**

Best Regards,
Daisy Zhou

Please remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact [email protected].

Why expired certificates are not in revoked folder (2024)
Top Articles
Reserve Bank of India - Press Releases
20 Countries with the Highest Homeless Population
This website is unavailable in your location. – WSB-TV Channel 2 - Atlanta
Star Sessions Imx
1970 Chevelle Ss For Sale Craigslist
Summit County Juvenile Court
Coffman Memorial Union | U of M Bookstores
Academic Integrity
Free VIN Decoder Online | Decode any VIN
Oppenheimer & Co. Inc. Buys Shares of 798,472 AST SpaceMobile, Inc. (NASDAQ:ASTS)
Vocabulario A Level 2 Pp 36 40 Answers Key
shopping.drugsourceinc.com/imperial | Imperial Health TX AZ
2024 Non-Homestead Millage - Clarkston Community Schools
The Shoppes At Zion Directory
Leeks — A Dirty Little Secret (Ingredient)
Echo & the Bunnymen - Lips Like Sugar Lyrics
The most iconic acting lineages in cinema history
Guidewheel lands $9M Series A-1 for SaaS that boosts manufacturing and trims carbon emissions | TechCrunch
Dr. med. Uta Krieg-Oehme - Lesen Sie Erfahrungsberichte und vereinbaren Sie einen Termin
Unlv Mid Semester Classes
Blackwolf Run Pro Shop
Free Online Games on CrazyGames | Play Now!
If you bought Canned or Pouched Tuna between June 1, 2011 and July 1, 2015, you may qualify to get cash from class action settlements totaling $152.2 million
zom 100 mangadex - WebNovel
8005607994
Biografie - Geertjan Lassche
Emuaid Max First Aid Ointment 2 Ounce Fake Review Analysis
*!Good Night (2024) 𝙵ull𝙼ovie Downl𝚘ad Fr𝚎e 1080𝚙, 720𝚙, 480𝚙 H𝙳 HI𝙽DI Dub𝚋ed Fil𝙼yz𝚒lla Isaidub
Kiddie Jungle Parma
Broken Gphone X Tarkov
Little Caesars Saul Kleinfeld
What Time Is First Light Tomorrow Morning
Why Gas Prices Are So High (Published 2022)
Albertville Memorial Funeral Home Obituaries
Ticket To Paradise Showtimes Near Marshall 6 Theatre
Michael Jordan: A timeline of the NBA legend
Sam's Club Gas Prices Florence Sc
Invalleerkracht [Gratis] voorbeelden van sollicitatiebrieven & expert tips
2 Pm Cdt
Obituaries in Hagerstown, MD | The Herald-Mail
Callie Gullickson Eye Patches
Jetblue 1919
Unveiling Gali_gool Leaks: Discoveries And Insights
Divinity: Original Sin II - How to Use the Conjurer Class
What to Do at The 2024 Charlotte International Arts Festival | Queen City Nerve
Devotion Showtimes Near Showplace Icon At Valley Fair
New Starfield Deep-Dive Reveals How Shattered Space DLC Will Finally Fix The Game's Biggest Combat Flaw
Argus Leader Obits Today
Craigslist Indpls Free
Ff14 Palebloom Kudzu Cloth
Www Extramovies Com
Latest Posts
Article information

Author: Twana Towne Ret

Last Updated:

Views: 6416

Rating: 4.3 / 5 (44 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Twana Towne Ret

Birthday: 1994-03-19

Address: Apt. 990 97439 Corwin Motorway, Port Eliseoburgh, NM 99144-2618

Phone: +5958753152963

Job: National Specialist

Hobby: Kayaking, Photography, Skydiving, Embroidery, Leather crafting, Orienteering, Cooking

Introduction: My name is Twana Towne Ret, I am a famous, talented, joyous, perfect, powerful, inquisitive, lovely person who loves writing and wants to share my knowledge and understanding with you.