So if I uncheck Publish Delta CRLs to this location then run certutil -crl do I also need to reissue the IntermediateCA cert and distribute it to remove the reference to the delta crl?
How do I remove the DeltaCRL location from an intermediate certificate
Our Intermediate CA shows that a there is a DeltaCRL like. It references a list that is not copied over to the webserver host the crl because we have blocked smb file sharing. So my questions are:
- Should I remove the DeltaCRL is should it be kept?
- How do I remove the DeltaCRL? Unchecking publish Delta on file://xxxx did not work
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
3 answers
Sort by: Most helpful
-
HLBui 13,020 Reputation points Independent Advisor
2026-09-23T23:05:05.0333333+00:00 Hi Daniel
Delta CRLs can be confusing when they’re hanging around but not actually being published to your web distribution point. In most environments, you don’t have to keep a DeltaCRL unless you’ve got apps or services that specifically rely on shorter revocation intervals. If you’re not publishing them to the web server and you’ve blocked SMB, then clients won’t be able to use them anyway, so it’s usually cleaner to remove them and just stick with the base CRL. The supported way to do that is to go into the CA properties, open the Extensions tab, and remove the delta CRL publication path (both file and HTTP if present). Just unchecking the “Publish Delta CRL” box isn’t always enough you may need to actually delete the delta entry from the list of CRL Distribution Points and then restart the CA service. After that, issue a new base CRL so clients have a fresh copy without delta references. Always double‑check that your applications don’t depend on delta CRLs before you make the change, but in most setups they’re optional.
-
AI answer
2026-09-23T21:31:02.7766667+00:00 Keep the delta CRL only if clients need timely revocation updates and the delta CRL is actually published to an HTTP location that clients can reach. If the delta CRL URL in issued certificates points to a location that is inaccessible, certificate validation can fail for some clients and services.
For internet-facing or off-network validation, the important requirement is that the CA publishes an accessible base CRL, and if delta CRLs are used, those delta CRLs must also be published to reachable HTTP URLs. Microsoft Entra ID guidance also requires a corresponding base CRL when a delta CRL distribution point is configured.
To remove or correct the delta CRL behavior on the intermediate CA:
- Open Certification Authority.
- Right-click the intermediate CA, then select Properties.
- Open the Extensions tab.
- Set Select extension to CRL Distribution Point (CDP).
- Review each CDP entry separately:
- For HTTP locations intended for clients, the documented client-facing options are:
- Include in CRLs. Clients use this to find Delta CRL locations
- Include in the CDP extension of issued certificates
- For file locations intended only for publishing, the documented publishing options are:
- Publish CRLs to this location
- Publish Delta CRLs to this location
- For HTTP locations intended for clients, the documented client-facing options are:
If the problem is that the CA is trying to publish delta CRLs to a blocked
file://path, clearing only Publish Delta CRLs to this location affects publishing to that file location, but it does not remove delta CRL references from client-facing CDP entries.To fully remove the delta CRL location from certificates, remove or update the CDP entry that clients use for delta CRLs:
- In the CDP list, select the HTTP or other client-facing location that has Include in CRLs. Clients use this to find Delta CRL locations enabled.
- Clear that checkbox for the entry, or remove that CDP entry and replace it with the correct reachable HTTP URL.
- If needed, add a reachable HTTP CDP location and configure it appropriately.
- If a file path is still needed only as a local publish target, keep the
file://entry but use only the publishing checkboxes required for your design.
Important effects:
- Changes to CDP URLs affect only newly issued certificates. Previously issued certificates continue to reference the original CRL location.
- If a delta CRL distribution point is configured without a corresponding base CRL distribution point, Microsoft Entra ID can return AADSTS500177.
- For external clients, publish CRLs on an HTTP location accessible outside the organization.
If the goal is to stop using delta CRLs entirely on this intermediate CA, ensure that no client-facing CDP entry includes the delta CRL option, and publish only the base CRL to an accessible HTTP location.
References:
AI-generated content may be incorrect. Read our transparency notes for more information.