import contact signed certificate and root ca

import contact signed certificate and root ca

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
import contact signed certificate and root ca RickyVene 09-28-2007
Posted by =?Utf-8?B?Umlja3lWZW5l?= on September 28, 2007, 9:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I've imported the contact certificate ".cer" both signed certificate and
root ca. And still the certificate on the email when clicked is giving me
warning: the certificate revocation list needed to verify the signing
certificate is either unavailable or it has expired.

But the certificates are not expired. How do you make this email
certificate be trusted on the signed email?

Thanks,
Ricky

Posted by Paul Adare on September 29, 2007, 6:16 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On Fri, 28 Sep 2007 18:36:01 -0700, RickyVene wrote:

> Hi,
>
> I've imported the contact certificate ".cer" both signed certificate and
> root ca. And still the certificate on the email when clicked is giving me
> warning: the certificate revocation list needed to verify the signing
> certificate is either unavailable or it has expired.
>
> But the certificates are not expired. How do you make this email
> certificate be trusted on the signed email?

You need to read the error message again. It isn't complaining that the
certificate is expired, it is complaining that the certificate revocation
list is either expired or unavailable. The fact that you had to install the
root cert would indicate that this is likely an internal PKI and that the
CRL is simply not externally available. Check the certificate for the CDP
URL and see if you can get to it.

--
Paul Adare
MVP - Virtual Machines
http://www.identit.ca
Transistor: A sibling, opposite of transbrother.

Posted by =?Utf-8?B?Umlja3lWZW5l?= on September 30, 2007, 2:45 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
My company's internet domain is domain.com but my AD domain is
domain01.local. Is it possible to add the CRL distribution like this
"http://www.domain.com/certutil/cadomain.crl"?

Because documents say "it needs to be FQDN" so I need to add
"http://computerca.domain01.local/certutil/cadomain.crl". If it's like this,
this can't be seen on the internet.

Please clarify and more power, I'm waiting for your second book in PKI to be
published.



Thanks,
Ricky



"Paul Adare" wrote:

> On Fri, 28 Sep 2007 18:36:01 -0700, RickyVene wrote:
>
> > Hi,
> >
> > I've imported the contact certificate ".cer" both signed certificate and
> > root ca. And still the certificate on the email when clicked is giving me
> > warning: the certificate revocation list needed to verify the signing
> > certificate is either unavailable or it has expired.
> >
> > But the certificates are not expired. How do you make this email
> > certificate be trusted on the signed email?
>
> You need to read the error message again. It isn't complaining that the
> certificate is expired, it is complaining that the certificate revocation
> list is either expired or unavailable. The fact that you had to install the
> root cert would indicate that this is likely an internal PKI and that the
> CRL is simply not externally available. Check the certificate for the CDP
> URL and see if you can get to it.
>
> --
> Paul Adare
> MVP - Virtual Machines
> http://www.identit.ca
> Transistor: A sibling, opposite of transbrother.
>

Similar ThreadsPosted
certificate import Wizard on Vista not working: February 5, 2008, 2:31 pm
Re: EFS Certificate Self Signed Vs. User Cert May 26, 2005, 12:28 am
MSSOAP refuses to accept self-signed certificate March 30, 2006, 11:43 am
CA root certificate May 22, 2008, 9:27 am
Add a Root Certificate Server October 12, 2005, 11:08 am
Renaming a Certificate Root authority June 28, 2006, 5:16 pm
Remove Certificate Server (root CA) October 31, 2007, 10:56 pm
Question about pkiview.msc Root Certificate Expiring February 15, 2008, 4:16 am
Change validatiy period of a Root certificate September 10, 2008, 11:05 pm
Root certificate authority no longer added to client machines December 15, 2006, 8:15 am

The site map in XML format XML site map

Contact Us | Privacy Policy