This is article is applicable to Windows Server 2008 R2. This article will be very helpful in order to address a specific issue identified by a Best Practices Analyzer scan. The main thing to remember is that you can use this procedure only on the computers that have the Active Directory Certificate Services Best Practices Analyzer run against them and are experiencing the issue addressed by this topic.
| Operating System | Windows Server 2008 R2 |
| Product/Feature | Active Directory Certificate Services |
| Severity | Warning |
| Category | Configuration |
Issue
The other thing to remember is that the Certification Authority isn’t configured to comprise the authority information access locations in the extension of issued certificates. Moreover, the authority information access extension provides the network location of the issuing CA’s certificate.
Impact
Clients may not be able to locate the issuing CA’s certificate to build a certificate chain, and certificate validation may fail.

