AD-CFG-20 - CRL distribution points count should be retrievable
Overviewβ
Certificate Revocation Lists (CRLs) are published at specific locations called CRL distribution points. These endpoints enable relying parties (including AD-integrated components) to check whether certificates have been revoked.
If CRL distribution points are missing, misconfigured, or reduced unexpectedly, revocation checking can fail. That can allow previously revoked certificates to remain effectively trusted longer than intended.
Monitoring the count of CRL distribution points helps detect:
- Missing distribution points after CA configuration changes
- Unexpected additions (potentially pointing to untrusted or incorrect publishing locations)
Security Recommendationβ
- Ensure CRL distribution points are configured to reliable, access-controlled endpoints.
- Validate that all intended distribution points are present and reachable from relying-party networks.
- Alert on changes to the number of distribution pointsβtreat deviations as configuration drift.
How the Test Worksβ
The test inspects AD configuration for CRL distribution point entries, counts them, and reports the current number. This provides a lightweight indicator that your revocation publication settings align with expected CA configuration.
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-CFG-20 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Config |
| PowerShell test | Test-MtAdCrlDistributionPointsCount |
| Tags | AD, AD-CFG-20, AD.Config |
Sourceβ
- Pester test:
tests/ad/config/Test-MtAdCrlDistributionPointsCount.Tests.ps1 - PowerShell source:
powershell/public/ad/config/Test-MtAdCrlDistributionPointsCount.ps1

