mrbios Posted September 2, 2022 Posted September 2, 2022 Really struggling to solve this one, as i feel like i've done what i needed to do to fix the underlying issue but it's still not working properly.... I'm running an offline CA with online sub ca PKI setup. The Offline CA crl expires after 12 months. Until the offline CA CRL expired windows hello for business was working perfectly. When it expired devices stopped working. I then replaced the crl with a new one issued from the offline CA..... that fixed the problem for a very short period, and now it's stopped working again even though the CRL's are valid. pkiview shows everything as happy. The only online forum conversation i've found about that outlines exactly the same process as i've done, replacing the CRL to update them then waiting a few hours. Has anyone else encountered this issue or got any suggestions for steps i might have missed?
mrbios Posted September 2, 2022 Author Posted September 2, 2022 Yep. There's two CDP Locations and two AIA locations, an LDAP one of each and a HTTP one of each. where the http one is http://pki.domain.net/pki/rootca.crl
free780 Posted September 2, 2022 Posted September 2, 2022 I'd move to cloud trust as it reduces the need to make PKI changes. https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-trust As long as the domain controller can reach the OSCP / CRL location in a Hybrid Trust deployment it should be OK. 1
mrbios Posted September 6, 2022 Author Posted September 6, 2022 Ace, thanks, that was far simpler. Cloud trust has done the trick
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now