IIS CRL Checking

From: Jackson Lancaster (jackson.lancaster_at_afbudsys.disa.mil)
Date: 09/05/03


Date: Fri, 5 Sep 2003 13:55:16 -0500


Can anyone explain (in some detail) how IIS checks CRL's for client PKI
certs. The articles I have seen state that IIS uses the CRL CDP to verify
client certificates. Is this true that IIS will use http or ldap (live) to
verify a cert against a CRL. I have also read that IIS caches the CRL's
that it downloads. Does it cache them in memory or in the file system. And
last, if I install CRL's locally, does IIS use these CRL's to verify client
certs or does it still check against the cached or real CRL? I have tried
installing CRL's locally (on the IIS server) but when I do this the pop-up
screen to choose a client cert to use takes about 20-30 seconds longer to
pop-up than if I dont have the CRL's installed locally.



Relevant Pages

  • Re: IIS CRL Checking
    ... > Can anyone explain how IIS checks CRL's for client PKI ... The articles I have seen state that IIS uses the CRL CDP to verify ... > certs or does it still check against the cached or real CRL? ...
    (microsoft.public.inetserver.iis.security)
  • Re: Problem with IIS5 - "expired" CRLs not working?
    ... I am not an expert on IIS, but I would need some more information to help ... CryptoAPI is returning the right status to IIS ... > The problem is that when the CRL in the ICA is expired, ... >> certs as an indicator that revocation does not need to be checked. ...
    (microsoft.public.platformsdk.security)
  • Re: Problem with IIS5 - "expired" CRLs not working?
    ... I am not an expert on IIS, but I would need some more information to help ... CryptoAPI is returning the right status to IIS ... > The problem is that when the CRL in the ICA is expired, ... >> certs as an indicator that revocation does not need to be checked. ...
    (microsoft.public.inetserver.iis)
  • RE: IIS 5.0 CRL management
    ... > I did some tests on certificate revocation but it doesn't seem to work ... > I revoked a client certificate, I checked that the CRL was modified but IIS ...
    (microsoft.public.inetserver.iis)
  • Re: IIS CRL Checking
    ... Certificate Revocation Lists (CRL) and IIS 5.0: ... > Can anyone explain how IIS checks CRL's for client PKI ... > certs or does it still check against the cached or real CRL? ...
    (microsoft.public.inetserver.iis.security)