Re: Cert Server Denying Certs requests - Event ID 21: The certificate is revoked

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 09/27/04


Date: Mon, 27 Sep 2004 18:25:15 GMT

Weird? Something was refreshed or cache cleared with shutting down
everything. Glad you got your certificate though. --- Steve

"seb" <seb@spam> wrote in message
news:eoUXeeGpEHA.2948@TK2MSFTNGP11.phx.gbl...
> It's working again. Not sure what exactly help, but had to turn off all
> servers, including domain controllers, for power maintenance and after
> that
> I was able to get certifcates again.
> regards
> Seb
>
>
> Użytkownik "Seb" <seb@no.spam> napisał w wiadomości
> news:eZKNjS6oEHA.536@TK2MSFTNGP11.phx.gbl...
>> Oh, one more thing:
>> I was able to enroll for certificates for this device few times, things
>> changed when I enforced publish new CRL. Seems CA wasn't checking CRL for
>> revoked certificates, when old CRL was valid.
>> Is any way to edit or clear revoked certificates database?
>> Seb
>>
>> Użytkownik "Steven L Umbach" <n9rou@n0-spam-for-me-comcast.net> napisał w
>> wiadomości news:o8%4d.359907$8_6.103251@attbi_s04...
>> > Ok. I can't be of much more help as I have never used mscep to request
>> > a
>> > cetificate for a router. The revoked certificate error is puzzling in
> that
>> > a revoked certificate is a problem if a revoked certiticate is being
> used
>> > for authentication. You are requesting a new certificate. Unless your
> old
>> > certificate is being used for authentication in the process somehow. --
>> > Steve
>> >
>> >
>> > "Seb" <seb@no.spam> wrote in message
>> > news:OMCeFymoEHA.2912@TK2MSFTNGP10.phx.gbl...
>> >> Thank you for response Steve.
>> >> I'm requesting new certificate using mscep.
>> >> I'm generating new keys set on router side, getting CA certificate,
>> >> authenticating using key obtained by mscep web page, and trying to
>> >> enroll. At end on router side I receive message that enrollment was
>> >> rejected by CA, and on server side logs message about error in
>> >> processing.
>> >> Seb
>> >>
>> >> Użytkownik "Steven L Umbach" <n9rou@n0-spam-for-me-comcast.net>
>> >> napisał
> w
>> >> wiadomości news:qrZ4d.252107$Fg5.27132@attbi_s53...
>> >>> How are you trying to request it? Can the CA issue any computer
>> >>> certificates? Since you revoked the old one make sure your request is
>> >>> for "new keys" and not existing key set. --- Steve
>> >>>
>> >>>
>> >>> "seb" <seb@spam> wrote in message
>> >>> news:OWc%23YBkoEHA.3392@TK2MSFTNGP15.phx.gbl...
>> >>>> I'm trying to get a new certificate to my router. I revoked the old
> one
>> >>>> and
>> >>>> now I
>> >>>> wanted to get a new one. Each time I go and ask for one I get the
>> >>>> Following
>> >>>> on the CA Server (on Windows2000):
>> >>>>
>> >>>> Event Type: Error
>> >>>>
>> >>>> Event Source: CertSvc
>> >>>> Event Category: None
>> >>>> Event ID: 21
>> >>>> Certificate Services could not process request XX due to an error:
> The
>> >>>> certificate is revoked.
>> >>>>
>> >>>> Anyone know how to solve or workaround this?
>> >>>>
>> >>>> Thanks
>> >>>>
>> >>>> Seb
>> >>>>
>> >>>>
>> >>>>
>> >>>>
>> >>>
>> >>>
>> >>
>> >>
>> >
>> >
>>
>>
>
>



Relevant Pages

  • Re: Proposal for a new PKI model (At least I hope its new)
    ... it is online and it is dynamic. ... What is your solution in place of PKI and certificates? ... > distributed real-time CRL model. ... absolutely know all possible relying parties ... ...
    (sci.crypt)
  • RE: CLR and AIA publishing properties unclear
    ... enterprise issuing CA and a web server hosting CRL and AIA for external ... include path in certificates. ... I do however publish CRL and deltas, CRL path should be ... should be included in certificates and delta CRL path in CRL's. ...
    (microsoft.public.windows.server.general)
  • CLR and AIA publishing properties unclear
    ... enterprise issuing CA and a web server hosting CRL and AIA for external ... I am however in doubt of a few CRL/AIA publishing properties. ... include path in certificates. ... I do however publish CRL and deltas, CRL path should be ...
    (microsoft.public.windows.server.general)
  • Problems with CRL
    ... I issued selfsigned root certificate, then issued user certificates signed ... Before I issued second root new CRL always replaced the old one. ... And when I revoke certificate issued by old root, ...
    (microsoft.public.platformsdk.security)
  • Re: Client Certificates Deleted after 2003 upgrade.
    ... I'm assuming that when you say that "none of the user certificates are ... CRL (which was presumably on the Cert Server machine). ... Server, and have CRL checking enabled, ...
    (microsoft.public.inetserver.iis.security)