| Status | Object | Finding | Date |
|---|---|---|---|
| OK | CONTOSO-ISSUING-CA | CA service on pki01.contoso.local is responding. 14 templates published. |
| Status | Object | Finding | Date |
|---|---|---|---|
| Warning | CONTOSO-ISSUING-CA | Signed with the outdated hash algorithm SHA-1. Recommendation: Switch the CA to SHA-256 and renew the CA certificate. Modern clients and browsers partly reject SHA-1. | |
| Warning | CONTOSO-ISSUING-CA | Valid for another 214 days. Found in: Enterprise CA CONTOSO-ISSUING-CA, AIA container (AD), NTAuth store. This is the current certificate of an enterprise CA. Recommendation: Renew the CA certificate in time. A CA never issues certificates that outlive its own certificate, so new certificates are already getting shorter lifetimes. | 2027-04-27 12:34 |
| Info | OLD-ROOT-CA | Expired CA certificate is still published in AD (AIA container (AD)). Recommendation: Can be removed after review (certutil -viewdelstore) so that clients do not load outdated certificates. | 2024-07-17 12:34 |
| OK | CONTOSO-ROOT-CA | Valid for another 2900 days. Found in: Trusted Root CAs (AD), AIA container (AD). | 2034-09-03 12:34 |
| Status | Object | Finding | Date |
|---|---|---|---|
| Critical | CONTOSO-ROOT-CA - Base CRL (HTTP) | CRL valid for another 5 days (validity period 180 days, typical for an offline CA). Number 11, 0 entries. Location: http://pki.contoso.com/CertEnroll/CONTOSO-ROOT-CA.crl. Recommendation: Offline CA: start the CA, sign a new CRL with "certutil -crl" and copy it to all CDP locations (AD and web server). Put the next renewal date in your calendar. | 2026-09-30 12:34 |
| Warning | http://pki.contoso.com/CertEnroll/CONTOSO-ISSUING-CA.crl | Stale copy: CRL number 409, another location already has number 412. Recommendation: Check publishing to this location (copy job, share, CA write permissions). Clients may load an outdated or soon-to-expire list from here. | |
| OK | CONTOSO-ISSUING-CA - Base CRL (LDAP) | CRL is current, next update 2026-10-01 12:34. Number 412, 37 entries. Location: CN=CONTOSO-ISSUING-CA,CN=pki01,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=contoso,DC=local. | 2026-10-01 12:34 |
| Status | Object | Finding | Date |
|---|---|---|---|
| Critical | http://pki.contoso.com/CertEnroll/CONTOSO-ISSUING-CA+.crl | CRL cannot be downloaded (404). Used in: certificates issued by CA CONTOSO-ISSUING-CA. Recommendation: Delta CRL with "+" in its name: enable "allowDoubleEscaping" for the CDP directory in IIS (request filtering). | |
| OK | http://pki.contoso.com/CertEnroll/pki01_CONTOSO-ISSUING-CA.crt | CA certificate can be downloaded (CONTOSO-ISSUING-CA, valid for another 214 days). Used in: certificates issued by CA CONTOSO-ISSUING-CA. |
| Status | Object | Finding | Date |
|---|---|---|---|
| OK | CONTOSO-ISSUING-CA | Current CA certificate is present in the NTAuth store. |
| Status | Object | Finding | Date |
|---|---|---|---|
| Critical | rds-gw.contoso.com | Valid for another 4 days. Template: Web Server, requester: CONTOSO\admin, request ID 8812, CA CONTOSO-ISSUING-CA. Recommendation: Renew the certificate or find out why autoenrollment does not kick in. If it is no longer needed, let it expire deliberately. | 2026-09-29 12:34 |
| Warning | wlan-radius.contoso.local | Valid for another 19 days. Template: RAS and IAS Server, requester: CONTOSO\NPS01$, request ID 7310, CA CONTOSO-ISSUING-CA. Recommendation: Renew the certificate or find out why autoenrollment does not kick in. If it is no longer needed, let it expire deliberately. | 2026-10-14 12:34 |
| Info | CONTOSO-ISSUING-CA | 1,284 valid issued certificates, 402 subject/template combinations; 2 of them expire within the next 30 days and have not been renewed yet. |
| Status | Object | Finding | Date |
|---|---|---|---|
| Info | Other servers | Only this machine was checked. Certificates on other servers (IIS, RDS, Exchange, LDAPS) were not included. | |
| OK | PKI01 | 6 certificates in the computer store, none expires within the next 30 days. |