Urgent - Subordinate Ceritication Authority Certificate Expired

Urgent - Subordinate Ceritication Authority Certificate Expired

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Urgent - Subordinate Ceritication Authority Certificate Expired clemente 04-02-2007
Posted by =?Utf-8?B?Y2xlbWVudGU=?= on April 2, 2007, 2:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I have an offline CA Root.
My enterprise CA certificate expired last saturday.
Last friday i have new certificate installed on the enterprise CA and all
worked fine.

Today when i reach the office i have on the Enterprise CA console general
tab a list of two certificates one is expired an the other is ok. On my
Domain Controllers i have an autoenrollment error that says that the DC cant
get the certificate from the Enterprise CA:

"Automatic certificate enrollment for local system failed to enroll for one
Domain Controller certificate (0x80092013). The revocation function was
unable to check revocation because the revocation server was offline."

I couldnt find any articles that can help on this so usual operation. Nobody
have problems with this?
How can i remove the CA expired certificate? Do u think its because of the
old certificate in the CA that the DCs couldt get the certificate?

I dont know what to do... Please any ideas would be appreciated.

TIA,

Clemente
Portugal


Posted by Nick Domukhovsky on April 2, 2007, 11:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Hi,
>
> I have an offline CA Root.
> My enterprise CA certificate expired last saturday.
> Last friday i have new certificate installed on the enterprise CA and all
> worked fine.
>
> Today when i reach the office i have on the Enterprise CA console general
> tab a list of two certificates one is expired an the other is ok. On my
> Domain Controllers i have an autoenrollment error that says that the DC cant
> get the certificate from the Enterprise CA:
>
> "Automatic certificate enrollment for local system failed to enroll for one
> Domain Controller certificate (0x80092013). The revocation function was
> unable to check revocation because the revocation server was offline."
>
> I couldnt find any articles that can help on this so usual operation. Nobody
> have problems with this?
> How can i remove the CA expired certificate? Do u think its because of the
> old certificate in the CA that the DCs couldt get the certificate?
>
> I dont know what to do... Please any ideas would be appreciated.
>
> TIA,
>
> Clemente
> Portugal
>

Looks like you have problems with CRLs.
My suggestions.
1. Your new CA's certificate includes invalid CDPs (check with certutil
-url <newCAcert filename>. If so - correct CDPs at your offline root
and reissue certificate for your CA.
2. CRL of your offline root also expired! Reissue CRL at offline root
and republish it to your CDPs.


--
With best regards
Nickolay Domukhovsky, MCSA

Similar ThreadsPosted
How to remove the Subordinate Enteprise CA expired certificate April 3, 2007, 9:38 am
Renew Subordinate CA certificate July 16, 2008, 8:21 pm
Expired security certificate January 25, 2007, 4:51 pm
Verisign certificate expired - who do we buy to update? September 14, 2007, 10:50 am
Re: certificate expired - vba macros now disabled - 50 documents... May 27, 2005, 12:53 am
what type of certificate authority? June 16, 2005, 4:08 pm
Certificate Authority type June 16, 2005, 6:01 pm
Problem with certificate authority January 27, 2006, 9:03 am
Certificate Authority (CA) - Failover Possible? February 24, 2006, 8:20 pm
Microsoft Certificate Authority June 14, 2006, 8:25 am

The site map in XML format XML site map

Contact Us | Privacy Policy