To specify certificate revocation list distribution points in issued certificates

  1. Log on to the system as an Administrator.
  2. Open Certification Authority
  3. In the console tree, click the certification authority.
  4. On the Action menu click Properties.
  5. On the Policy Module tab, click Configure.
  6. On the X.509 Extensions tab, under CRL Distribution Points, specify the distribution points.
    To Do this
    Add a new certificate revocation list (CRL) distribution point. Click Add, and type in the name of the new CRL distribution point.
    Remove a CRL distribution point from the list. Click the CRL distribution point, then click Remove.
    Indicate that you do not want to use a URL as a CRL distribution point. Clear the URL's check box.
    Indicate that you want to use a URL as a CRL distribution point. Select the URL's check box.
  7. Stop and restart the Certificate Services service.

note Note

Working with MMC console files

Certificate revocation

Revoke an issued certificate

Schedule the publication of the certificate revocation list

Manually publish the certificate revocation list

View the certificate revocation list