ADCS Health Check by certmon.de

State of your Microsoft PKI · Domain contoso.local (DEMO)
Created 2026-09-25 12:34
on PKI01 · version 0.2.0
Overall status
Critical
Immediate action required
3
Critical
4
Warnings
6
OK
3
Notes

Environment

Domaincontoso.local (DEMO)
Enterprise CAsCONTOSO-ISSUING-CA
CA certificates in AD4
Checked asCONTOSO\admin

Certification authorities

StatusObjectFindingDate
OKCONTOSO-ISSUING-CACA service on pki01.contoso.local is responding. 14 templates published.

CA certificates

StatusObjectFindingDate
WarningCONTOSO-ISSUING-CASigned with the outdated hash algorithm SHA-1.
Recommendation: Switch the CA to SHA-256 and renew the CA certificate. Modern clients and browsers partly reject SHA-1.
WarningCONTOSO-ISSUING-CAValid for another 214 days. Found in: Enterprise CA CONTOSO-ISSUING-CA, AIA container (AD), NTAuth store. This is the current certificate of an enterprise CA.
Recommendation: Renew the CA certificate in time. A CA never issues certificates that outlive its own certificate, so new certificates are already getting shorter lifetimes.
2027-04-27 12:34
InfoOLD-ROOT-CAExpired CA certificate is still published in AD (AIA container (AD)).
Recommendation: Can be removed after review (certutil -viewdelstore) so that clients do not load outdated certificates.
2024-07-17 12:34
OKCONTOSO-ROOT-CAValid for another 2900 days. Found in: Trusted Root CAs (AD), AIA container (AD).2034-09-03 12:34

Revocation lists (CRL)

StatusObjectFindingDate
CriticalCONTOSO-ROOT-CA - Base CRL (HTTP)CRL valid for another 5 days (validity period 180 days, typical for an offline CA). Number 11, 0 entries. Location: http://pki.contoso.com/CertEnroll/CONTOSO-ROOT-CA.crl.
Recommendation: Offline CA: start the CA, sign a new CRL with "certutil -crl" and copy it to all CDP locations (AD and web server). Put the next renewal date in your calendar.
2026-09-30 12:34
Warninghttp://pki.contoso.com/CertEnroll/CONTOSO-ISSUING-CA.crlStale copy: CRL number 409, another location already has number 412.
Recommendation: Check publishing to this location (copy job, share, CA write permissions). Clients may load an outdated or soon-to-expire list from here.
OKCONTOSO-ISSUING-CA - Base CRL (LDAP)CRL is current, next update 2026-10-01 12:34. Number 412, 37 entries. Location: CN=CONTOSO-ISSUING-CA,CN=pki01,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=contoso,DC=local.2026-10-01 12:34

CDP/AIA availability

StatusObjectFindingDate
Criticalhttp://pki.contoso.com/CertEnroll/CONTOSO-ISSUING-CA+.crlCRL cannot be downloaded (404). Used in: certificates issued by CA CONTOSO-ISSUING-CA.
Recommendation: Delta CRL with "+" in its name: enable "allowDoubleEscaping" for the CDP directory in IIS (request filtering).
OKhttp://pki.contoso.com/CertEnroll/pki01_CONTOSO-ISSUING-CA.crtCA certificate can be downloaded (CONTOSO-ISSUING-CA, valid for another 214 days). Used in: certificates issued by CA CONTOSO-ISSUING-CA.

NTAuth

StatusObjectFindingDate
OKCONTOSO-ISSUING-CACurrent CA certificate is present in the NTAuth store.

Issued certificates

StatusObjectFindingDate
Criticalrds-gw.contoso.comValid for another 4 days. Template: Web Server, requester: CONTOSO\admin, request ID 8812, CA CONTOSO-ISSUING-CA.
Recommendation: Renew the certificate or find out why autoenrollment does not kick in. If it is no longer needed, let it expire deliberately.
2026-09-29 12:34
Warningwlan-radius.contoso.localValid for another 19 days. Template: RAS and IAS Server, requester: CONTOSO\NPS01$, request ID 7310, CA CONTOSO-ISSUING-CA.
Recommendation: Renew the certificate or find out why autoenrollment does not kick in. If it is no longer needed, let it expire deliberately.
2026-10-14 12:34
InfoCONTOSO-ISSUING-CA1,284 valid issued certificates, 402 subject/template combinations; 2 of them expire within the next 30 days and have not been renewed yet.

Local certificate store

StatusObjectFindingDate
InfoOther serversOnly this machine was checked. Certificates on other servers (IIS, RDS, Exchange, LDAPS) were not included.
OKPKI016 certificates in the computer store, none expires within the next 30 days.

This check is a snapshot.

CRLs and certificates keep expiring every day. ADCS Monitor watches your PKI continuously, also checks the certificates on all your servers and alerts you by email or Teams before Wi-Fi, VPN or RDP go down. One-time license instead of a subscription, runs entirely inside your network.
Join the waitlist
Questions or need help with a finding? mail@247-it.com