Re: Smart Card logon on W2K Network...

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 04/29/05


Date: Thu, 28 Apr 2005 17:27:48 -0500

The computer/application will refer to the certificate details page - CRL
distribution points to find the CRL so you need to configure such before you
start issuing certificates. The link below should be able to help you out on
how to modify CRL distribution points. Possibly an internal website or
fileshare would work for you. --- Steve

http://www.microsoft.com/technet/security/topics/cryptographyetc/tshtcrl.mspx

"bill" <bill@discussions.microsoft.com> wrote in message
news:59ABE337-9990-4D62-9374-772322A00D39@microsoft.com...
> Hi security gurus,
>
> I'm currently trying to implement smart card logon on my company's W2K AD
> network. So far, I've set up (in a test environment of course) an internal
> Enterprise CA and am also using third-party certificates to validate the
> cards. My question pertains to CRL's, or specifically, the retrieval of
> the
> CRL. Currently, the CDP on the card points to an LDAP site, but for
> testing
> purposes I am operating in a closed network.
>
> My question is, if I have a current copy of the CRL, how exactly do I
> enter
> it into AD and point the cards to retrieve it from there instead of the
> site
> that's on the card? Is this even possible? Thank you in advance.



Relevant Pages

  • Re: Proposal for a new PKI model (At least I hope its new)
    ... it is online and it is dynamic. ... What is your solution in place of PKI and certificates? ... > distributed real-time CRL model. ... absolutely know all possible relying parties ... ...
    (sci.crypt)
  • RE: CLR and AIA publishing properties unclear
    ... enterprise issuing CA and a web server hosting CRL and AIA for external ... include path in certificates. ... I do however publish CRL and deltas, CRL path should be ... should be included in certificates and delta CRL path in CRL's. ...
    (microsoft.public.windows.server.general)
  • CLR and AIA publishing properties unclear
    ... enterprise issuing CA and a web server hosting CRL and AIA for external ... I am however in doubt of a few CRL/AIA publishing properties. ... include path in certificates. ... I do however publish CRL and deltas, CRL path should be ...
    (microsoft.public.windows.server.general)
  • Problems with CRL
    ... I issued selfsigned root certificate, then issued user certificates signed ... Before I issued second root new CRL always replaced the old one. ... And when I revoke certificate issued by old root, ...
    (microsoft.public.platformsdk.security)
  • Re: Client Certificates Deleted after 2003 upgrade.
    ... I'm assuming that when you say that "none of the user certificates are ... CRL (which was presumably on the Cert Server machine). ... Server, and have CRL checking enabled, ...
    (microsoft.public.inetserver.iis.security)