Re: Need advice for CA Model

From: John McCoy (jmccoy_at_cmatech.com)
Date: 04/30/03


Date: Wed, 30 Apr 2003 15:41:16 -0400


Here is the error message. Error 0x80090325: The certificate chain was
issued by an untrusted authority.

We have published the Enterprise Root crl as well as the subordinate crl.It
chains correctly and we verified we can open both url's from the outside
world.

For some reason it isn't working. Any ideas?

Thanks

"S. Pidgorny [MVP]" <slavickp@yahoo.com> wrote in message
news:uyLMxjvDDHA.1616@TK2MSFTNGP11.phx.gbl...
> John, some details about the error message would be nice to have... I
think
> it can be related not to the CA but to the CRL that needs to be made
> available whereever the CA certificates are used. It's perfectly fine to
> publish CRL from the root CA.
>
> --
> Svyatoslav Pidgorny, MS MVP, MCSE
> -= F1 is the key =-
>
> "John McCoy" <jmccoy@cmatech.com> wrote in message
> news:#ROTx6oDDHA.3072@TK2MSFTNGP11.phx.gbl...
> >an error it can't chain back to the
> > root CA when connecting, we haven't published The root CA for security
> > cocerns, is it safe to do this? We think not.
> >
>
>



Relevant Pages

  • Re: Need advice for CA Model
    ... John, some details about the error message would be nice to have... ... publish CRL from the root CA. ...
    (microsoft.public.win2000.security)
  • Re: Certificates
    ... I request a cert and issue the cert from the Root CA. ... I can browse to the crl using http, ... Why can't the subordinate CA ... more of a case that it cannot validate the chain. ...
    (microsoft.public.security)
  • Help PKI installation - lots of questions !
    ... One STAND ALONE ROOT CA called SACAMX00 (SA stand for Stand Alone, ... AMERICAS Sub & CA ASIA Sub ... Client use this to find Delta CRL ... publish my CRL again even if no certificate are revoked? ...
    (microsoft.public.security)
  • Re: Help PKI installation - lots of questions !
    ... One STAND ALONE ROOT CA called SACAMX00 (SA stand for Stand Alone, ... AMERICAS Sub & CA ASIA Sub ... Client use this to find Delta CRL ... publish my CRL again even if no certificate are revoked? ...
    (microsoft.public.security)
  • Re: Offline Root CA
    ... You can change the CRL interval to be of a long ... > We plan to use 2 Certificate Authorities. ... Our Root will be a StandAlone ... We will then install a Subordinate Enterprise CA. ...
    (microsoft.public.win2000.security)