Re: Revocation error when logging onto a Win2k domain with a smartcard

From: Paul Adare - MVP - Microsoft Virtual PC (padare_at_newsguy.com)
Date: 07/28/04


Date: Wed, 28 Jul 2004 05:11:22 -0400

In article <4b08eb79.0407260443.4f1131e2@posting.google.com>, in the
microsoft.public.win2000.security news group, Dave Heckford
<dheckford@blueyonder.co.uk> says...

> As far as I'm aware the CRL's are replicating around the domain
> controllers fine and are updating without user intervention. If anyone
> can help or suggest any ideas that I can try I'd be very greatful.
>

You'll need to describe your PKI in more detail for us here. There are a
number of requirements regarding CRLs and smart cards, and without
details of your PKI, it is going to be tough to help you out here.

In the interim, this may help somewhat:

http://www.microsoft.com/technet/prodtechnol/winxppro/support/tshtcrl.ms
px

or

http://tinyurl.com/4kbmn

Also check out
http://support.microsoft.com/default.aspx?scid=kb;en-us;281245

Although this is for 3rd paty CAs, the requirements are the same for
Windows Server CAs it is just that most of the requirements will be
taken care of for you.

-- 
Paul Adare
This posting is provided "AS IS" with no warranties, and confers no
rights.