Digital Certs - Revoked - Register Quicker?

Digital Certs - Revoked - Register Quicker?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Digital Certs - Revoked - Register Quicker? Frank 04-25-2006
Posted by =?Utf-8?B?RnJhbms=?= on April 25, 2006, 12:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I setup a Windows 2k3 Certificate Authority (CA) server and it's working just
as planned. I forced our IIS website (Win 2k) to only allow users who have a
Certificate from my Win2k3 CA server. Now I set the CRL Publication interval
to 1 hr on the Win2k3 CA server.

When I revoke a user (certificate) it takes the full 1 hr before the user
can no longer access the site. Is there anyway to force the IIS server to
check the CA everytime someone tries to access the site? I figured (on the
Win2k3 CA server) if you right click Revoked Cerfiticates -> All Tasks ->
Publish, this would let the IIS server know that the CRL has changed, and
here is a list of all the revoked certs. Am I missing something? Thanks for
all your help.

-Frank

Posted by Miha Pihler [MVP] on April 25, 2006, 3:12 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi Frank,

CRLs are cached on the server and clients and as long as that CRL is valid
(not expired) there is no supported way to force the client/server to check
for new (updated) CRL.

If you need to revoke users access permission immediately, you have to
either disable user's account or remove the account from the group that
allows him/her access to the website.

--
Mike
Microsoft MVP - Windows Security

>I setup a Windows 2k3 Certificate Authority (CA) server and it's working
>just
> as planned. I forced our IIS website (Win 2k) to only allow users who have
> a
> Certificate from my Win2k3 CA server. Now I set the CRL Publication
> interval
> to 1 hr on the Win2k3 CA server.
>
> When I revoke a user (certificate) it takes the full 1 hr before the user
> can no longer access the site. Is there anyway to force the IIS server to
> check the CA everytime someone tries to access the site? I figured (on the
> Win2k3 CA server) if you right click Revoked Cerfiticates -> All Tasks ->
> Publish, this would let the IIS server know that the CRL has changed, and
> here is a list of all the revoked certs. Am I missing something? Thanks
> for
> all your help.
>
> -Frank



Similar ThreadsPosted
Digital certs June 13, 2008, 11:17 am
keystrokes register January 30, 2007, 5:33 pm
Question on autoenrollment process with revoked certificate. April 1, 2007, 4:01 am
Question on autoenrollment process with revoked certificate April 1, 2007, 2:03 pm
Microsoft Security Advisory (912840): How to re-register dll? January 6, 2006, 9:32 am
How do I delete my old ca certs... February 19, 2008, 10:45 am
subordinate ent CAs don't publish certs to AD after Win 2k3 SP1 July 23, 2005, 1:00 pm
MS-CHAP V2 and server certs November 20, 2006, 9:23 am
using certs in non-domain environments: January 23, 2008, 10:40 pm
Generate Verisign certs for one or two year ? August 9, 2005, 1:08 pm

The site map in XML format XML site map

Contact Us | Privacy Policy