Re: Problem publishing crl on EntCA

From: Jack Wang [MSFT] (jackwa_at_online.microsoft.com)
Date: 07/30/04


Date: Fri, 30 Jul 2004 06:40:23 GMT

Hi David,

This issue is strange. Could you let us know the exact command you are
using? Just the "certutil -crl" command? Also, it will be greatly
appreciated if you provide the detail steps to solve the issue. I would
like to know more about how you delete the publication of crl to local
drive and readd the command line. We will try to provide some analyse based
on the information.

Have a great day!

Sincerely,
Jack Wang, MCSE 2000/2003, MCSA 2000/2003, MCDBA, MCSD
Microsoft Partner Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
| From: "David Beaven" <technet@ids.ac.uk>
| References: <#YJrDlAcEHA.3580@TK2MSFTNGP11.phx.gbl>
| Subject: Re: Problem publishing crl on EntCA
| Date: Fri, 23 Jul 2004 13:08:37 +0100
| Lines: 25
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2800.1106
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
| Message-ID: <eFagb4KcEHA.2816@TK2MSFTNGP11.phx.gbl>
| Newsgroups: microsoft.public.windows.server.security
| NNTP-Posting-Host: idsnat.ids.ac.uk 139.184.194.221
| Path:
cpmsftngxa06.phx.gbl!TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11
phx.gbl
| Xref: cpmsftngxa06.phx.gbl microsoft.public.windows.server.security:4295
| X-Tomcat-NG: microsoft.public.windows.server.security
|
| Solved it. Deleted publication of crl to local drive. Readded the same
| line (cut and pasted syntax) and started working again!
| Weird - minor bug?
|
|
|
| "David Beaven" <technet@ids.ac.uk> wrote in message
| news:#YJrDlAcEHA.3580@TK2MSFTNGP11.phx.gbl...
| > Have an offline root CA and have created an online enterprise CA.
| Verified
| > certificate chain ok and crl and aia for root are available in htpp and
ad
| > locations. e.g pkihealth snapin says ok for rootCA.
| > Configured enterprise ca extensions for crl and aia. When I attempt to
| > publish crl 'certutil -crl' I get: CRL command failed: 0x800700a1
| > (WIN32/HTTP: 161), the specified path is invalid. I have tried removing
| all
| > extensions paths except local file system - but still same error (I
assume
| > that it publishes crls to the locations specified in extensions tab?!).
| > Any ideas please?
| > Thanks
| > David
| >
| >
|
|
|