Re: CAPICOM documentation

From: Rafa Llarena (rafallg_at_dif.um.es)
Date: 03/28/05

  • Next message: Rhett Gong [MSFT]: "RE: InitiliazeSecurityContext makes tckt for samaccountname instea"
    Date: Mon, 28 Mar 2005 09:27:55 +0200
    
    

     I'm writting a web service who will check certificates' validity using CRL
    checking. The main problem is that I get different results when I test it
    with different certificates. I check the flag CHECK_ONLINE_ALL. With some
    certificates it goes online (I use Ethereal), it finds the CRL and the CDP
    sends it. But it doesn't matter if the certificate is revoked or not, the
    result is always "Revocation Status Unknown". At first I thought it may be
    because of the timeout, but I've read somewhere here that it's duration is
    ten seconds, so I don't think this is the reason.
    With other certificates, and this is what seems more strange for me, even
    with the CHECK_ONLINE_ALL it never goes online to search the CRL (and there
    is no CRL installed, I've removed them all using certmgr.exe). Why?
    Does CAPICOM need any specific format in the CDP extension field?
    I have other question about using web services. How can I give ASPNET user
    access permissions to all stores? Now I'm using impersonation in the
    web.config file, specifying user name and password. Is there any other way
    to do this?
    I hope my english is not too bad.
    Thank you very much

    Rafael Llarena

    "Alon Bar-Lev" <alon@xor-t.com> escribió en el mensaje
    news:ulSlRZ8LFHA.3184@TK2MSFTNGP09.phx.gbl...
    > Ask the question...
    >


  • Next message: Rhett Gong [MSFT]: "RE: InitiliazeSecurityContext makes tckt for samaccountname instea"

    Relevant Pages

    • Re: Proposal for a new PKI model (At least I hope its new)
      ... it is online and it is dynamic. ... What is your solution in place of PKI and certificates? ... > distributed real-time CRL model. ... absolutely know all possible relying parties ... ...
      (sci.crypt)
    • RE: CLR and AIA publishing properties unclear
      ... enterprise issuing CA and a web server hosting CRL and AIA for external ... include path in certificates. ... I do however publish CRL and deltas, CRL path should be ... should be included in certificates and delta CRL path in CRL's. ...
      (microsoft.public.windows.server.general)
    • CLR and AIA publishing properties unclear
      ... enterprise issuing CA and a web server hosting CRL and AIA for external ... I am however in doubt of a few CRL/AIA publishing properties. ... include path in certificates. ... I do however publish CRL and deltas, CRL path should be ...
      (microsoft.public.windows.server.general)
    • Problems with CRL
      ... I issued selfsigned root certificate, then issued user certificates signed ... Before I issued second root new CRL always replaced the old one. ... And when I revoke certificate issued by old root, ...
      (microsoft.public.platformsdk.security)
    • Re: Client Certificates Deleted after 2003 upgrade.
      ... I'm assuming that when you say that "none of the user certificates are ... CRL (which was presumably on the Cert Server machine). ... Server, and have CRL checking enabled, ...
      (microsoft.public.inetserver.iis.security)