Re: Validity period of certificates is not accepted anymore

From: Sebastian Rieger (sebastian.rieger_at_gwdg.de)
Date: 11/25/04


Date: Thu, 25 Nov 2004 14:59:22 +0100

David Cross [MS] schrieb:
> The CA policy module will always truncate the validity of an issued cert to
> be within the lifetime of its own validity period. You must renew the CA
> with a longer lifetime to avoid this.
>

Thanks for your help! The feature of reducing the lifetime of a
certificate is great! I renewed the ca certificate though, to avoid
having users register their certificate a short time before the ca
certificate expires. I've got two valid CA certificates now (same key,
different life time) which seems to work fine even with the CRL etc.

Thanks to you I now know that there seems to be no registry key or the
like, to avoid the life time from being cut down.

I've got a new problem now, though! The life time of the certificate is
accepted (or shortened) by the policy module, but it states that there
are no SMIME capability extensions set. There used to be an extension
for this, but right now Netscape / Mozilla requests lack it.

The policy modules rejects all requests of our users, complaining about
the lacking extension (0x80094805 (-2146875387)). I couldn't find
anything in TechNet or on the Microsoft webpage.

Strange thing is, requests sent in by an Internet Explorer are accepted
by the policy module. They ought to be constructed on the client side,
using Xenroll.dll, right? Selecting them from the pending request list,
and showing their extension works (the extensions contain the four
encryption types of SMIME capabilities, which are also set in
defaultSMIME registry key).

Any help would (again) be greatly appreciated! Thanks again, for your
advice!

Sebastian Rieger



Relevant Pages

  • MS CA and policy module with VB 6.0
    ... i'm doing research on this field and have created a test policy module (made ... specific extension and this works fine. ... certificate the certificate intended purpose shows (looking at the ...
    (microsoft.public.platformsdk.security)
  • Re: MS CA and policy module with VB 6.0
    ... There is no ICertEncode* interface for the EKU extension. ... > i'm doing research on this field and have created a test policy module for our test environment. ... But when I look at the issued> certificate the certificate intended purpose shows (looking at the ...
    (microsoft.public.platformsdk.security)
  • Re: Problem with Windows 2003 Certificate Server CDP
    ... There is no difference in the way Microsoft clients validate certificate ... To get an issued certificate to contain the second representation would ... require a custom policy module that reads, ... > CRL Distribution Point ...
    (microsoft.public.platformsdk.security)
  • Re: Validity period of certificates is not accepted anymore
    ... The CA policy module will always truncate the validity of an issued cert to ... be within the lifetime of its own validity period. ... Best Practices for implementing Windows Server 2003 PKI: ... Troubleshooting Certificate Status and Revocation whitepaper: ...
    (microsoft.public.platformsdk.security)
  • Windows 2000 Certificate Service Question
    ... I had a question about Microsoft Certificate Services an Policy Modules. ... I have a MS Certificate Server on a different domain that we are using to ... Policy Module" in the Failed Requests folder. ...
    (microsoft.public.win2000.advanced_server)