Re: Certificate Service - Revoke Question

From: Steve Riley \(MSFT\) (steriley@microsoft.com)
Date: 12/21/02


From: "Steve Riley \(MSFT\)" <steriley@microsoft.com>
Date: Fri, 20 Dec 2002 21:28:09 -0800


You could also configure the CRL to publish more frequently.

http://www.microsoft.com/windows2000/en/server/help/default.asp?url=/windows
2000/en/server/help/sag_CSprocsAutoPubCRL.htm

--
--------------------------------
Steve Riley
MCS Security Consulting Practice
steriley@microsoft.com
--------------------------------
"Greg" <msdn_newsgroup@pickpro.com> wrote in message
news:01b301c2a861$0100a9f0$d4f82ecf@TK2MSFTNGXA11...
> Nothing like answering your own question...
>
> You must right click on "Revoked Certificates" and
> choose "Publish" to update the CRL.
>
>
>
> >-----Original Message-----
> >Good morning...
> >
> >Recently setup a Remote access server to require EAP for
> >authentication.  I have an enterprise certificate
> >authority running and I'm issuing certificates and giving
> >remote users access without problems.  However, when I
> >revoke a certificate, access to the client machine
> >continues to work.  Is there something else I need to do,
> >some time period this will take?
> >
> >Thanks-
> >
> >Greg
> >.
> >


Relevant Pages

  • Problems with CRL
    ... I issued selfsigned root certificate, then issued user certificates signed ... Before I issued second root new CRL always replaced the old one. ... And when I revoke certificate issued by old root, ...
    (microsoft.public.platformsdk.security)
  • Re: Clustering Certificate Authority Server
    ... Delta CRL - Publish every 24 hours, ... Amihai ... >> Can you think of a way that the second CA will be able to revoke ... >> certificates or sign the CRL using the private key of the first CA? ...
    (microsoft.public.windows.server.security)
  • Re: Proposal for a new PKI model (At least I hope its new)
    ... it is online and it is dynamic. ... What is your solution in place of PKI and certificates? ... > distributed real-time CRL model. ... absolutely know all possible relying parties ... ...
    (sci.crypt)
  • RE: CLR and AIA publishing properties unclear
    ... enterprise issuing CA and a web server hosting CRL and AIA for external ... include path in certificates. ... I do however publish CRL and deltas, CRL path should be ... should be included in certificates and delta CRL path in CRL's. ...
    (microsoft.public.windows.server.general)
  • Re: Untrusted certificates with Friendly Name of "Fraudlent, NOT Microsoft"?
    ... The certificates *are* revoked. ... > find it helpful when I have many Thawte freemail certs. ... >>> Expiration just means it is old and all certificates expire. ... >>> certificate and perform a revoke check (by downloading the latest ...
    (microsoft.public.security)