Certificate Question

From: Nancy Kafer (nkafer_at_homesteaderslife.com)
Date: 08/24/04


Date: Tue, 24 Aug 2004 15:30:06 -0500

I have issued several certificates for our remote users (on Win2K3 Ent
Server). I have configured the CRL distribution points and everything
appears to be fine. I have a couple of basic questions:

I need to revoke a certificate because a user has left the company. I went
into the Certificate Authority on the Issuing CA and revoked the
certificate, republished the CRLs to the distribution points.

1) How can I make sure that the client machine is using the most recent CRL?
2) Should the certificate that was revoked be delete from the machine? Once
the certificate has been revoked I would like to make sure the client
machine receives the CRL and deletes the certificate from the local computer
store. Seems to me at one point I saw a place to configure the deletion of a
revoked certificate from the client machine but I can't seem to find it now.
Can anyone help me out?

Thanks.



Relevant Pages

  • Re: Certificate revokation
    ... Is there a way to revoke a certificate and that the revokation will be ... > delta CRL that can be published every few hours with only the changes ... As long as it is valid clients can cache it and use ...
    (microsoft.public.windows.server.security)
  • Re: Certificate Question
    ... Client can use any cached CRL as long as it is valid. ... The other thing you can do is design your Base and Delta CRL ... Once the client gets new CRL it will not allow use of that certificate ... > I need to revoke a certificate because a user has left the company. ...
    (microsoft.public.windows.server.security)
  • Re: Problems with CRL after renewal
    ... recognize a CRL as being authoritative for a given CA ... > Before renewal I could revoke any issued certificate and function> CertGetCertificateChain shows that it is revoked. ... > MSDN and support the CA Version extension and Authority Key Id extension. ...
    (microsoft.public.platformsdk.security)
  • Re: Certificate Question
    ... "Nancy Kafer" wrote... ... the new CRL is used everywhere). ... Certificates" section of certificate store. ... > revoked I would like to make sure the client machine ...
    (microsoft.public.windows.server.security)
  • Re: Certificate revokation
    ... > Is there a way to revoke a certificate and that the revokation ... The revocation will be in effect when you issue the first CRL after ...
    (microsoft.public.windows.server.security)