Problem publishing crl on EntCA

From: David Beaven (technet_at_ids.ac.uk)
Date: 07/22/04

  • Next message: Edgar E. Cayce: "Windows 2003 Server, Constant Logon/Logoff in my Security Log - does this mean something is worng?"
    Date: Thu, 22 Jul 2004 17:28:38 +0100
    
    

    Have an offline root CA and have created an online enterprise CA. Verified
    certificate chain ok and crl and aia for root are available in htpp and ad
    locations. e.g pkihealth snapin says ok for rootCA.
    Configured enterprise ca extensions for crl and aia. When I attempt to
    publish crl 'certutil -crl' I get: CRL command failed: 0x800700a1
    (WIN32/HTTP: 161), the specified path is invalid. I have tried removing all
    extensions paths except local file system - but still same error (I assume
    that it publishes crls to the locations specified in extensions tab?!).
    Any ideas please?
    Thanks
    David


  • Next message: Edgar E. Cayce: "Windows 2003 Server, Constant Logon/Logoff in my Security Log - does this mean something is worng?"

    Relevant Pages

    • Questions about new PKI infrastructure
      ... I'm about to implement a PKI infrastructure in my company, ... Certificate key length: 4.096 bits ... CRL and AIA publication order: ...
      (microsoft.public.windows.server.general)
    • RE: Questions about new PKI infrastructure
      ... Root CA: ... Certificate key length: 4.096 bits ... CRL and AIA publication order: ...
      (microsoft.public.windows.server.general)
    • RE: Questions about new PKI infrastructure
      ... What should and should not be specified in the CAPolicy.inf for the root ... Do I only have to worry about CDP, AIA, key length and ... should I use 77 or 79 as the CRL publishing option? ...
      (microsoft.public.windows.server.general)
    • Re: MS CA service and publish CRL and AIA
      ... To have the windows 2000 CA automatically publish CRLs to another location, ... >>servers) as a CDP and AIA extension and check the box> for publishing the CRL ... >>checking the boxes to include the link in issued> certificate and CRL's). ...
      (microsoft.public.win2000.security)
    • Re: Offline Root Certificate Server and subordinate CA
      ... the application will look for the CRL or CA certificate if it needs it. ... > It appears that I did not correctly set up my CRL and AIA publication ... > I deployed my enterprise offline root and subordinate CA with these ...
      (microsoft.public.win2000.security)