New Install/New problems with CRLs...

From: Ohaya (ohaya_at_cox.net)
Date: 09/21/03


Date: Sat, 20 Sep 2003 20:04:29 -0400


Hi,

I installed a set of machines:

- MachineA: Windows Server 2003 configured as domain controller, with
Active Directory and IIS installed

- MachineB: Windows Server 2003 - not on the MachineA domain, but on a
workgroup (MISNET), and with Certificate Server (and IIS) installed.
Certificate Server is configured as a Standalone CA.

- MachineC: Windows 2000 Pro - this is my client machine

Using Certificate Server on MachineB, I've been able to create/issue
server and client certificates, which I've installed on MachineA and
MachineC, respectively, and I have client authentication working,

BUT....

No matter what I've done so far, I cannot get the CRL/revocation working
at all.

I've revoked a test client certificate on the Certificate Server on
MachineB, and published the CRL, but the client cert still seems to be
working.

I've rebooted MachineA, start/stopped IIS, etc., and still the client
cert works.

I've confirmed that I can access the .CRL file from MachineA, so I am
completely puzzled.

Does anyone have any suggestions????

Thanks,
Jim



Relevant Pages

  • IIS CRL Checking is really driving me crazy!!
    ... working with SSL and client certs/authentication in various ... It seems like with each different configuration this ... Certificate Server setup as a Standalone Certificate Server. ... Windows Server 2003 - not on the MachineA domain, ...
    (microsoft.public.platformsdk.security)
  • Re: Problem with local policy while connecting to a terminal server
    ... MCSE, CCEA, Microsoft MVP - Terminal Server ... I would have posted this under win2003 terminal services .. ... I have win2003 standard server (MachineA) into which I normally ... I was then still able to logon to terminal ...
    (microsoft.public.win2000.termserv.clients)
  • Re: IIS CRL Checking is really driving me crazy!!
    ... whatis the CRL publication interval? ... be expired before any new CRLs will be loaded by the IIS server. ... It seems like with each different configuration this ... > - MachineA: Windows Server 2003 configured as domain controller, ...
    (microsoft.public.platformsdk.security)
  • IUSR account replication outside Active Directory
    ... My ASP pages, published in IIS 5.0 on MachineA, are trying to read ... server. ... Microsoft Access Driver] The Microsoft Jet database engine cannot open the ... account in MachineB I cannot do it because MachineA is not in the Active ...
    (microsoft.public.inetserver.iis.security)
  • Re: VNC on current running KDE desktop
    ... >> currently running X server instead of making a new one. ... > configuration i just install it and them reboot X i assume? ... You don't have to restart X, you just need to run x0rfbserver. ... given that you are at machineB, but want to access machineA that is ...
    (Debian-User)