Re: Revocation error when logging onto a Win2k domain with a smartcard

From: Dave Heckford (dheckford_at_blueyonder.co.uk)
Date: 07/30/04


Date: 30 Jul 2004 05:38:28 -0700

Hi Tim,

I've tried connecting to the crl location via internet explorer and
get prompted to download a file, I'm presuming this file is the crl.
When I click save it asks for a location to save to so I tell it to go
in the Temporary Internet files within Documents and settings as I
believe that is the correct location for it. I'm assuming with this
action the client machine can see the CDP correctly to find the CRL.

Thanks,

Dave

"Tim Springston [MSFT]" <tspring@online.microsoft.com> wrote in message news:<Oerl3GCdEHA.1000@TK2MSFTNGP12.phx.gbl>...
> Hi Dave-
>
> From the machine where you see this error can you reach the specified CRL?
> CRLs are commonly HTTP URLs, possibly LDAP ones. If you don't recall the
> specific URLs you should be able to find them by opening the Certificates
> snapin for the user or machine and opening the specific certificate.
>
> If the certificate is one on the smartcard you may need to use software from
> the manufacturer to look at the certificate fields.
>
> The essential idea is to make sur ethat you can get to the CRL from that
> client. Please repost and let us know if this helps.
> --
> Tim Springston
> Microsoft Corporation
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
> "Dave Heckford" <dheckford@blueyonder.co.uk> wrote in message
> news:4b08eb79.0407260443.4f1131e2@posting.google.com...
> > Hi,
> >
> > I'm having quite a few problems with Smartcard logon. Each time I try
> > to logon to certain Win2k Professional workstation I get the following
> > message:-
> > "The revocation function was unable to check revocation
> > because the revocation server was offline"
> >
> > To elimate sites I have moved a workstation that has this problem from
> > one site to another but the problem persists. I have removed the
> > workstation from the domain and re-added it back in, No difference. So
> > far all I know is if you use ctrl+alt+del everything is OK but as soon
> > as you use a smartcard I keep getting the error message.
> >
> > As far as I'm aware the CRL's are replicating around the domain
> > controllers fine and are updating without user intervention. If anyone
> > can help or suggest any ideas that I can try I'd be very greatful.
> >
> > Thanks,
> >
> > Dave



Relevant Pages

  • Re: Thawte Digital Certificate Revocation List Issue
    ... > I am new to digital certificates and cannot get the Thawte certificate ... It's been awhile since I played with the Thawte certificates. ... Microsoft requires the cert ... CRL so Outlook doesn't know where to get ...
    (microsoft.public.security)
  • Re: Newbie wants to learn about PKI Server 2003......
    ... 2003 PKI Certificate Security", and have been lurking here for a bit. ... We will implement a 2 tier heirarchy, with the Root CA being offline. ... All clients that attempt revocation checking will first attempt to retrieve the CRL from the ... level below a self-signed cert, so applications that are 3280 compliant would never check the ...
    (microsoft.public.windows.server.security)
  • Re: revoking ipsec certificate doesnt work
    ... It's possible to publish manually the update delta and full CRL using the CA ... MMC SnapIn on the Server. ... my test VPN client never checks if the ... Server 2003 SP1 without any problem after the certificate is revoked nearly ...
    (microsoft.public.windows.server.security)
  • Help PKI installation - lots of questions !
    ... One STAND ALONE ROOT CA called SACAMX00 (SA stand for Stand Alone, ... AMERICAS Sub & CA ASIA Sub ... Client use this to find Delta CRL ... publish my CRL again even if no certificate are revoked? ...
    (microsoft.public.security)
  • Re: Help PKI installation - lots of questions !
    ... One STAND ALONE ROOT CA called SACAMX00 (SA stand for Stand Alone, ... AMERICAS Sub & CA ASIA Sub ... Client use this to find Delta CRL ... publish my CRL again even if no certificate are revoked? ...
    (microsoft.public.security)