Monitor CRL refreshness
It is vital that CRL is fresh and available otherwise your PKI is not healthy. Often i hear that Customer create a reminder in ther calender. Even that kind of effort the PKI outage is quite common, and reson is CRL that have exiperd.
I stumbled over this tool get-crlfreshness. This powershell cmdlet in short terms check CDP location and verify freshness of it. It also have function for email alerts and all logged out to a logfile.
More information: https://blogs.technet.microsoft.com/russellt/2016/04/29/get-crlfreshness/
Leave a Reply