certificate authority

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: deheinz1 (deheinz1.194x2a_at_mail.webservertalk.com)
Date: 07/08/04


Date: Thu, 8 Jul 2004 06:59:06 -0500


Needing help on this

Trying to configure the root certificate authority CRL list to be
placed on the subordinate so the root can be off line.

Have configured stand alone root authority on a Windows 2000 box with
the capolicy.inf pointing the CRLDistributionPoint to the the
subordinate(placed in the systemroot dir). I also have added the
subordinate server into the root policy CRL list.
The CRL seems shows up correct on the certificate.

capolicy.inf
[Version]
Signature="$Windows NT$"

[CRLDistributionPoint]
URL="http://testca.test.gettysburg.edu/gbc/gbc.crl"

[certsrv_server]
RenewalKeyLength=4096
RenewalValidityPeriod=2
RenewalValidityPeriodUnits=Years

On the subordinate created a virtual directory where the CRL will be
placed. I moved the root CRL distribution list to the virtual
directory. I then get a certificate for the subordinate. It seems to
have the proper path for the CRL but it does not seem to use the CRL
list.

The subordinate certificate seems to have the correct CRL path but when
CRL is expired the subordinate fails until the root comes back on line
and I retrieve the CRL list from the root.

Any suggestions?

Thanks,

Dave

--
deheinz1
------------------------------------------------------------------------
Posted via http://www.webservertalk.com
------------------------------------------------------------------------
View this thread: http://www.webservertalk.com/message296112.html
 


Relevant Pages

  • Re: Certutil error
    ... After I ran cmd as an administrator it published the CRL and CRT file in the AD without error. ... I have your WS 2008 PKI and Certificate Security book. ... These surfaced when trying to publish my root ... CertUtil: A referral was returned from the server. ...
    (microsoft.public.security)
  • Re: Offline Root Certificate Server and subordinate CA
    ... It appears that I did not correctly set up my CRL and AIA publication ... I deployed my enterprise offline root and subordinate CA with these defaults. ...
    (microsoft.public.win2000.security)
  • Re: Newbie wants to learn about PKI Server 2003......
    ... 2003 PKI Certificate Security", and have been lurking here for a bit. ... We will implement a 2 tier heirarchy, with the Root CA being offline. ... All clients that attempt revocation checking will first attempt to retrieve the CRL from the ... level below a self-signed cert, so applications that are 3280 compliant would never check the ...
    (microsoft.public.windows.server.security)
  • Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
    ... If a subordinate chains to a trusted root CA, ... Best bet is for your to read the certificate revocation and status checking whitepaper that describes how certificates are verified. ...
    (microsoft.public.windows.server.security)
  • Certutil error
    ... After I ran cmd as an administrator it published the CRL and CRT file in the AD without error. ... I have your WS 2008 PKI and Certificate Security book. ... These surfaced when trying to publish my root ... CertUtil: A referral was returned from the server. ...
    (microsoft.public.security)