This error occurs when the certificate services tries to publish a CRL or Delta CRL to the listed container. This can happen after a recovery of a crashed server, or a hardware replacement. When you restore the certificate service configuration and database along with the server certificate, you must make sure that the server name does not change for the certificate to be valid. This error happens because the security for the CDP container is still set with the SID of the old server, but there is no entry for the new server. So, before rebuilding the server, some cleaning has to be done in the AD:
- remove the account of the old or crashed server.
- clean up the DNS if applicable
- in AD Sites and Services, locate the following container: Services\Public Key Services\CDP\<server name>\<server name>. For each entry, in the Properties\Security Tab, remove the entry for the old SID and add an entry for the computer account of the new server, giving it Full Control permissions.