Performance problems with auditing of "Start and stop Active Directory Certificate Services".

When configuring the auditing settings of a certificate authority, one is inclined to select the "Start and Stop Active Directory Certificate Services" option. However, this option may cause problems in some circumstances.

If this option is active, a checksum is calculated over the certification authority database when the certification authority service is stopped and started and written to the event log (events no. 4880 and 4881).

The duration of the calculation of this checksum depends on the size of the certification authority database. For a newly installed certification authority, this is still unproblematic due to the small database size. However, the larger the database becomes over time, the longer it takes to generate the checksum. During this time, the certification authority service seems to "hang" - it remains in the "being started" or "being terminated" state, and may well do so for several minutes. This can cause problems especially in the following situations:

The "Start and Stop Certificate Services" option should therefore only be activated if the event generated is also meaningfully evaluated, and the associated disadvantages are known and accepted.

Related links:

External sources

en_USEnglish