Re: getting the expiration date

From: Paul Adare - MVP - Microsoft Virtual PC (padare_at_newsguy.com)
Date: 09/06/04


Date: Mon, 6 Sep 2004 07:14:33 -0400

In article <9abefafc.0409060137.368fb908@posting.google.com>, in the
microsoft.public.security news group, Nils <hurzsoft@web.de> says...

> is there any way via script to check all the certificates on a
> certificate server (windows 2003) in order to read the according
> expiration dates and warn the users just in time ? We use iKey dongles
> (rainbow technologies) to do the authentication and sometimes the
> build-in warning routines inside the driver doesen't work. Hence it's
> very annoying if the user is on a business trip and wasn't aware that
> his certificate stored on the iKey has already expired. If some script
> could check the expiration dates periodically we can ask the users 1
> month before to renew their certificates.
>

Sure, you can do this via either the CyrptoAPI or CAPICOM. My partner
and I have developed just such a script that runs as a logon script,
checks the expirations of certificates in the local user's store, and
when a certificate is about to expire, submits a renewal request. You
can find details on both the CyrptoAPI and CAPICOM on the MSDN web site.

Rather than scripting your own solution though, I'd put pressure on the
vendor to fix whatever is wrong with their built-in warning routines.

-- 
Paul Adare
This posting is provided "AS IS" with no warranties, and confers no
rights.


Relevant Pages

  • getting the expiration date
    ... We use iKey dongles ... If some script ... could check the expiration dates periodically we can ask the users 1 ... month before to renew their certificates. ...
    (microsoft.public.security)
  • Re: Set Account Expiration Date for group in domain.
    ... I want to have each user from group_3 get disabled his account every 3 ... I think you mean password expiration date rather than account expiration ... applies to all users (if their passwords expire). ... would also have to be done with a script that runs on that day. ...
    (microsoft.public.windows.server.scripting)
  • Annual reminder query
    ... Some or our vendors need to be certified to various standards. ... The certificates include an expiration date, usually three or so years from ... that end I need to send out a notice requesting the statement. ... if a company's certificate is due to expire on 12/1/04, ...
    (microsoft.public.access.queries)
  • Re: Set Account Expiration Date for group in domain.
    ... I want to have each user from group_3 get disabled his account every 3 ... An account can have only one expiration date, ... applies to all users (if their passwords expire). ... would also have to be done with a script that runs on that day. ...
    (microsoft.public.windows.server.scripting)
  • Re: DateDIF
    ... > F10 = Days until expiration ... > However, if the certificate had expired; that is, if the value in E10 is ... >>> I have a sheet where I have in a column when the license was obtained ... >>> When the certificate expires I get an out of range error. ...
    (microsoft.public.excel.programming)