Standalone CA's and CRL

Standalone CA's and CRL

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Standalone CA's and CRL Gunna 08-27-2008
Posted by =?Utf-8?B?R3VubmE=?= on August 27, 2008, 9:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


When setting up a standalone CA on Server 2003 Standard you can select the
LDAP CRL publish location but since it is not an Enterprise CA does it still
publish the CRL into Active directory?

Reason I ask is I created a Root CA standlone on a Server 2003 standard
domain member. Then created a standalone subordinate on Server 2003 standard
domain member and it complained about not being able to check the CRL when I
grabed the cert from the Root. I understood this meant either the CRL isnt
publihsed or not reachable. Any ideas?

Posted by Brian Komar \(MVP\) on August 27, 2008, 11:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


You can select the publication point, but:
1) You must manual configure the LDAP path DSConfigDN where you define the
%6 value to the Configuration naming context
2) you must manually publish the CRL to the CDP location (and AIA if
defined) using certutil -dspublish

The standalone subordinate will not be able to get the CRl from the LDAP
path (if you use defaults)
the standalone has no idea about DCs and cannot resolve an LDAP:/// path to
be the nearest DC
So you must manually inject the updated root CRL into the cache by using
certutil -addstore root rootcrl.crl

Brian

> When setting up a standalone CA on Server 2003 Standard you can select the
> LDAP CRL publish location but since it is not an Enterprise CA does it
> still
> publish the CRL into Active directory?
>
> Reason I ask is I created a Root CA standlone on a Server 2003 standard
> domain member. Then created a standalone subordinate on Server 2003
> standard
> domain member and it complained about not being able to check the CRL when
> I
> grabed the cert from the Root. I understood this meant either the CRL
> isnt
> publihsed or not reachable. Any ideas?


Similar ThreadsPosted
Standalone Root- Standalone Sub September 13, 2005, 3:43 pm
Multiple CA's? January 24, 2008, 1:40 am
CA's and Certificates for MOM or System Center OM August 25, 2007, 11:28 am
3rd party CA's CRL cache in domain controller? October 30, 2007, 10:01 am
Where is the offline CA's certificate store ? How to retrieve the issued cert's? April 27, 2006, 3:49 pm
Standalone/ Enterprise CA issue October 18, 2005, 2:52 am
Restricted groups in a standalone computer October 17, 2006, 12:45 pm
PKI Cert for a website on a standalone server. September 24, 2007, 2:46 pm
Smart Card Authenticatyion to standalone PC January 10, 2008, 7:27 am
standalone CA - cannot use browser to install certs February 1, 2008, 3:41 pm

The site map in XML format XML site map

Contact Us | Privacy Policy