Getting IIS to check CRL

From: KH Koh (khkoh1@yahoo.com.sg)
Date: 12/31/02


From: "KH Koh" <khkoh1@yahoo.com.sg>
Date: Mon, 30 Dec 2002 21:03:30 -0800


Hi,

Got Certification Authority to work and set IIS 5.0 to
require client certificates. But when the certificate is
revoke, IIS still accepts it.

Question: How to get IIS to check the Certificate
Revocation List when authenicating the client certificates?

The microsoft knowledgebase on setting the
MD_CERT_NO_REVOC_CHECK key programmatically is not at all
helpful. If anyone has done this, would you be so kind to
explain in laymen's term.

Thanks ...



Relevant Pages

  • Re: security header is not present in the incoming message
    ... One certificate "Client Private.pfx" to Certificates - Current User, Personal, Certificates. ... One certificate "Server Private.pfx" to Certificates - Current User, Other People, Certificates and the third one "Server Public.cer" to Certificates, Personal, Certificates. ... And this goes for services run in IIS och in ASP.NET Development Server. ...
    (microsoft.public.dotnet.security)
  • Re: IIS Client Certificate Mapping
    ... > PKI Client Certificates? ... > required Client Certificates as well. ... > as the user has a certificate IIS allows access, ... That account can access the files ... ...
    (microsoft.public.inetserver.iis.security)
  • Re: Truly unique number for a computer.
    ... Have you looked at using "Client Certificates" for this? ... you can configure IIS to reject connection attempts from systems that ... that using IIS. ...
    (microsoft.public.dotnet.general)
  • Re: Changing CA CRLs
    ... Do client certificates need to be re-issued when authenticating using IIS? ... CDP information in the certificate that is listed/installed in the CTL. ...
    (microsoft.public.win2000.security)
  • Re: Generation of certificate using openssl
    ... >>You could just use the Certificates Services that comes with Windows 2000. ... I'd hate to think that IIS and OpenSSL-created ... > The OP obviously has some business reason to use OpenSSL on his CA - perhaps ...
    (microsoft.public.inetserver.iis.security)