I'm working with Microsoft's Public Key Infrastructure (PKI) and I'm interested to know more about how the expiration date of a CRL is determined and how it can be adjusted in a Microsoft PKI environment.
Specifically:
What factors and configurations determine the default expiration date/period for CRLs in Microsoft PKI? e.g. CRL itself is valid for 2 days, one week or six months
How can the CRL expiration date be modified or extended to better align with our organization's security policies and certificate lifecycle?
I'm aware of the difference between the CRL publication interval and the CRL expiration date. However, I'm interested in understanding the factors and configurations that influence the CRL expiration date.
What factors and configurations determine the default expiration date/period for CRLs in Microsoft PKI?
Internally the default is best guess if not specified. This is typically way more important for consumers that manually make offline copies of the CRL/ implementations that must use a CRL and not OCSP.