Note: Configure the Certification Distribution Point (CDP) and Authority Information Access (AIA) settings for Certificate Revocation List (CRL).
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
From Server Manager, click Tools > Certification Authority.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
From the left panel, right‑click the CA, and then click Properties > Extensions.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the Select extension menu, select CRL Distribution Point (CDP).
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the certificate revocation list, select the C:\Windows\system32\ entry, and then do the following:
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Select Publish CRLs to this location.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Clear Publish Delta CRLs to this location.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Delete all other entries except for C:\Windows\system32\.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Add.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the Location field, add http://serverIP/CertEnroll/<CAName><CRLNameSuffix><DeltaCRLAllowed>.crl, where serverIP is the IP address of the server.
Note: If your server is reachable by using the FQDN, then use the <ServerDNSName> instead of the server IP address.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click OK.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Select Include in the CDP extension of issued certificates for the created entry.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the Select extension menu, select Authority Information Access (AIA).
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Delete all other entries except for C:\Windows\system32\.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Add.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the Location field, add http://serverIP/CertEnroll/<ServerDNSName>_<CAName><CertificateName>.crt, where serverIP is the IP address of the server.
Note: If your server is reachable by using the FQDN, then use the <ServerDNSName> instead of the server IP address.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click OK.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Select Include in the AIA extension of issued certificates for the created entry.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Apply > OK.
Note: If necessary, restart the certification service.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
From the left panel, expand the CA, right‑click Revoked Certificates, and then click Properties.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Specify the value for CRL publication interval and for Publish Delta CRLs Publication interval, and then click Apply > OK.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
From the left panel, right‑click Revoked Certificates, click All Tasks, and then publish the New CRL.