Keep the delta CRL only if clients need timely revocation updates and the delta CRL is actually published to an HTTP location that clients can reach. If the delta CRL URL in issued certificates points to a location that is inaccessible, certificate validation can fail for some clients and services.
For internet-facing or off-network validation, the important requirement is that the CA publishes an accessible base CRL, and if delta CRLs are used, those delta CRLs must also be published to reachable HTTP URLs. Microsoft Entra ID guidance also requires a corresponding base CRL when a delta CRL distribution point is configured.
To remove or correct the delta CRL behavior on the intermediate CA:
- Open Certification Authority.
- Right-click the intermediate CA, then select Properties.
- Open the Extensions tab.
- Set Select extension to CRL Distribution Point (CDP).
- Review each CDP entry separately:
- For HTTP locations intended for clients, the documented client-facing options are:
- Include in CRLs. Clients use this to find Delta CRL locations
- Include in the CDP extension of issued certificates
- For file locations intended only for publishing, the documented publishing options are:
- Publish CRLs to this location
- Publish Delta CRLs to this location
- For HTTP locations intended for clients, the documented client-facing options are:
If the problem is that the CA is trying to publish delta CRLs to a blocked file:// path, clearing only Publish Delta CRLs to this location affects publishing to that file location, but it does not remove delta CRL references from client-facing CDP entries.
To fully remove the delta CRL location from certificates, remove or update the CDP entry that clients use for delta CRLs:
- In the CDP list, select the HTTP or other client-facing location that has Include in CRLs. Clients use this to find Delta CRL locations enabled.
- Clear that checkbox for the entry, or remove that CDP entry and replace it with the correct reachable HTTP URL.
- If needed, add a reachable HTTP CDP location and configure it appropriately.
- If a file path is still needed only as a local publish target, keep the
file://entry but use only the publishing checkboxes required for your design.
Important effects:
- Changes to CDP URLs affect only newly issued certificates. Previously issued certificates continue to reference the original CRL location.
- If a delta CRL distribution point is configured without a corresponding base CRL distribution point, Microsoft Entra ID can return AADSTS500177.
- For external clients, publish CRLs on an HTTP location accessible outside the organization.
If the goal is to stop using delta CRLs entirely on this intermediate CA, ensure that no client-facing CDP entry includes the delta CRL option, and publish only the base CRL to an accessible HTTP location.
References: