CRL caching and smart card logon

From: Uljas Käki (someone_at_microsoft.com)
Date: 11/28/05


Date: Mon, 28 Nov 2005 22:08:51 +0200

We are implementing smart card logon with third-party certificates. We have
Windows 2003 servers, Windows XP workstations and Windows 2003 CA (for
domain controller certificates).

As far as I have found out, when you log on with third-party certificates,
domain controllers check the published CRL, which is published in internet.
How about situation, when CRL is not available? For example, the CRL server
or WAN link is down for some reason, or the computer where the user is
logging on, does not have network connection (the user must have logged on
to that computer earlier succesfully, of course).

I know that in this kind of situations things work ok, for a while at least.
But if CRL server is down, or no domain controller is available (cached
credentials) for longer time, when can I start expecting trouble?
Theoretically, this situation could be that a person is on a vacation or on
a long business trip with his/her laptop, and has no connection to DC or CRL
point for, say, two months. Would there be some kind of trouble?

Are there some settings which would affect any of these?

Thanks, Uljas



Relevant Pages

  • Site-tosite VPN Issue
    ... Windows Server 2003 domain controller ... Mixture of PCs running Windows 2000 Profressional with SP3 and Windows XP ... the VPN to the Windows Server 2003 domain controller. ... 12.7MB file from the server to the client PC. ...
    (microsoft.public.windows.server.networking)
  • CRL caching and smart card logon
    ... Windows 2003 servers, Windows XP workstations and Windows 2003 CA (for ... when CRL is not available? ... But if CRL server is down, or no domain controller is available (cached ...
    (microsoft.public.security)
  • RE: Internet Connection Wizard failing at Firewall Config and Secu
    ... You can use the Dcdiag.exe (Domain Controller Diagnostic Tool) included ... in Windows Support Tools to verify the AD status. ... Windows Server 2003 Active Directory Diagnostics, ...
    (microsoft.public.windows.server.sbs)
  • RE: Provide feedback to DC promotion/replacement
    ... one of the is reffering to a Windows 2000 ... As i sad in the previous posts, to rename a domain controller ... controllers in the domain must be running Windows Server 2003. ... a global catalog. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Pre-authentication failed for Windows 2008 systems
    ... Failure Code: 0x19 ... Client Address: SERVER IP ... Our active directory domain consists of two windows 2003 R2 x64 ... On the domain controller, ...
    (microsoft.public.windows.server.security)