RE: IIS 5.0 CRL management

From: elair (elair_at_discussions.microsoft.com)
Date: 03/21/05


Date: Mon, 21 Mar 2005 08:57:06 -0800

Hi,

nobody encountered this kind of problems when working with IIS 5.0 ?

thanks

"elair" wrote:

> Hi,
>
> I'm working on a windows 2000 server with IIS 5.0 . I configured SSL with
> client authentication.
> I did some tests on certificate revocation but it doesn't seem to work
> correctly..
> I revoked a client certificate, I checked that the CRL was modified but IIS
> seems to use the former one (the client cert keeps working).
> I changed the date on the IIS server and then it works, the new CRL is
> retrieved .
>
> I have some questions on the CRL management on IIS 5.0 :
> I would like to know what is the default time period for retrieving a CRL on
> IIS 5.0, is it 1 day as on IIS 6.0 ?
> Is there a way to reduce this frequency on IIS 5.0 and how ?
> If the default time period is one day for example will the new CRL be
> retrieved after one day or will IIS wait the expiration date of the cached
> CRL ?
> I looked for the cache CRL in the windows 2000 directories but I didn't find
> them. Are they stored with a specific extension? they don't seem to be stored
> in memory, as when I restarted the computer it was still the former CRL that
> was used
>
>
> thanks
> regards
>
> elair
>



Relevant Pages

  • Re: IIS CRL Checking
    ... > Can anyone explain how IIS checks CRL's for client PKI ... The articles I have seen state that IIS uses the CRL CDP to verify ... > certs or does it still check against the cached or real CRL? ...
    (microsoft.public.inetserver.iis.security)
  • IIS CRL Checking
    ... Can anyone explain how IIS checks CRL's for client PKI ... The articles I have seen state that IIS uses the CRL CDP to verify ... certs or does it still check against the cached or real CRL? ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS CRL Checking
    ... Certificate Revocation Lists (CRL) and IIS 5.0: ... > Can anyone explain how IIS checks CRL's for client PKI ... > certs or does it still check against the cached or real CRL? ...
    (microsoft.public.inetserver.iis.security)
  • IIS 5.0 CRL management
    ... I did some tests on certificate revocation but it doesn't seem to work ... I revoked a client certificate, I checked that the CRL was modified but IIS ...
    (microsoft.public.inetserver.iis)
  • IIS 5.0 IN A DOMAIN?
    ... > I am contacting this list, because of the focus on security more than ... > Here are the client goals: ... > HAVE THE IIS AND SQL BOXES JOIN A SPECIAL DOMAIN DESIGNED JUST FOR THESE ... > WIN2KDOMAIN2 DOMAIN CONTROLLERNEEDED TO SUPPORT THIS? ...
    (Focus-Microsoft)

Loading