Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can view an expired certificate revocation list (CRL) as historical data, but it cannot confirm current revocation status. On Windows Server 2008 and 2012, a Certification Authority (CA) deletes expired CRLs when it issues a new CRL by default. If the list was not retained and has already been deleted, enabling retention now does not restore it.

First, identify what you need to check

Choose the method based on whether you need a historical record or a current revocation decision, and whether the CRL still exists.

  • Historical audit: Look for the CRL in the CA’s retained history or database. Retention must have been configured before the list was deleted.
  • Current certificate status: Obtain and validate the current CRL, or use the current revocation mechanism configured for your environment. An expired CRL’s issuer, update dates, and revoked entries may be useful historical evidence, but the expired list is not current.
  • A CRL file you already have: Use a viewer appropriate to the CA product and file format. Check whether the file is a full CRL or a delta CRL.

View expired CRL history in Windows Certification Authority

Microsoft’s instructions below are specifically for Windows Server 2008 and Windows Server 2012 Certification Authorities. Microsoft says those versions delete expired CRLs by default when a new CRL is issued. Verify the applicable procedure against documentation for your deployed server version rather than assuming it applies to every current Windows Server release. See Microsoft’s guidance on viewing expired CRLs.

Query the CA database

Run this command to query CRL publication-related fields in the CA database:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

certutil -view -out "CRLThisPublish,CRLNumber,CRLCount" CRL

Show CRL history in the console

Microsoft says the Certification Authority console hides CRL history by default. Enable the history view with:

certsvc.msc /e

Preserve expired CRLs for future audits

If you need expired CRLs for a future audit, Microsoft documents changing the CA setting before the audit. For the Windows Server 2008 and 2012 versions covered by its article, run:

certutil -setreg CACRLFlags -CRLF_DELETE_EXPIRED_CRLS

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Then restart the Certificate Services service:

net stop certsvc

net start certsvc

This is a CA configuration change, so follow your organization’s change-control process and verify version-specific guidance first. It preserves CRLs going forward; it does not recover a CRL that was already deleted.

Inspect a CRL with another certificate-management product

CRL viewing options depend on the product and the file or list type. Red Hat Certificate System documentation describes viewing a CRL’s header, complete list, cached CRL, Base64-encoded contents, or delta CRL. Those capabilities are specific to Red Hat Certificate System and should not be assumed to describe Microsoft CA behavior. Consult the documentation for the CA product and version that manages the list: Red Hat Certificate System 9 administration guide: Managing Certificates.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do not confuse an expired CRL with an expired certificate

A CRL has its own update period; a certificate has its own validity period. Those are separate conditions. Whether a service continues publishing revocation information for expired certificates can also depend on that service’s policy. For example, Hongkong Post says its CRL can be opened in Windows to view listed revoked certificates, and that its service does not publish revocation status for expired certificates in that CRL. That statement describes Hongkong Post’s policy, not a universal CRL rule. See its e-Cert FAQ.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.