CRL LDAP question...

CRL LDAP question...

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
CRL LDAP question... Mark 06-27-2006
Posted by =?Utf-8?B?TWFyaw==?= on June 27, 2006, 12:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Is there a tool that will validate/fetch a CRL via a LDAP distribution point?
A windows tool would be ideal. But I'll take anything.

Thanks in advance


Posted by Yogesh Mehta [MSFT] on June 27, 2006, 4:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You can use certutil to do this,
http://technet2.microsoft.com/WindowsServer/en/Library/a3d5dbb9-1bf6-42da-a13b-2b220b11b6fe1033.mspx?mfr=true

Thanks,
--
--
Yogesh Mehta [MSFT]

This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm

> Is there a tool that will validate/fetch a CRL via a LDAP distribution
> point?
> A windows tool would be ideal. But I'll take anything.
>
> Thanks in advance
>



Posted by Brian Komar on June 28, 2006, 8:30 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Mark@discussions.microsoft.com says...
> Is there a tool that will validate/fetch a CRL via a LDAP distribution point?
> A windows tool would be ideal. But I'll take anything.
>
> Thanks in advance
>
>
If you have a certificate with the mentioned LDAP distribution point,
the best command to use is
certutil -verify -urlfetch <certificate.cer>

The command will attempt to download all CRLs and CA certificates listed
in the AIA and CDP extensions. The command will do this for all
certificates in the chain up to a self-signed root certificate.

Another alternative is to use pkiview.msc from the WIndows Server 2003
Resource Kit tools. This tool provides a gui look to the CA hierarchy
and provides individual analysis of each AIA and CDP extension in the
cert chain.
http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-
4ae7-96ee-b18c4790cffd&displaylang=en

Brian

Similar ThreadsPosted
CRL CDP LDAP question... July 10, 2006, 9:20 am
LDAP December 15, 2005, 11:56 am
ldap security October 6, 2005, 8:16 pm
Ldap validate October 10, 2005, 6:11 am
Access Control to LDAP on AD? October 14, 2005, 9:20 pm
How to install LDAP? Newbie July 11, 2006, 7:33 pm
How to setup SSL LDAP between servers? July 12, 2006, 1:38 pm
Secure LDAP Configuration July 25, 2006, 1:06 pm
ldap distribution point September 24, 2007, 9:11 pm
firewall question and windows installer/spyware question September 24, 2006, 8:48 am

The site map in XML format XML site map

Contact Us | Privacy Policy