CA Troubles

From: Jaye (address_at_company.com)
Date: 08/05/05

  • Next message: Ste: "Re: Howto : programatically give NTAUTHORIRTY\Network Service account write permission on a directory"
    Date: Fri, 05 Aug 2005 14:51:21 -0600
    
    

    Hello,

    I am in the process of setting up a two-tier implentation of Certificate
    Services in a Windows 2003 Server environment (Offline Root and Online
    Issuing). I get all the way to the point of installing a requested
    certificate from my Offline Root to my Online Issuing and I get the
    following errors.

    --------------------------
    Cannot verify certificate chain. Do you wish to ignoew the error and
    continue? The revocation function was unable to check revocation
    because the revocation server was offline.
    --------------------------

    I click OK on that warning and then try to start the Certificate
    Services and get the following error.

    --------------------------
    The revocation function was unable to check revocation because the
    revocation server was offline.
    --------------------------

    Does anyone have any insight in to what is causing those errors?

    Thank you,

    ~Jaye


  • Next message: Ste: "Re: Howto : programatically give NTAUTHORIRTY\Network Service account write permission on a directory"

    Relevant Pages

    • Remoting through Authenticating Proxy using SSL
      ... certificate is invalid according to the validation procedure. ... function was unable to check revocation for the certificate. ... function was unable to check revocation because the revocation server was ... The network trace also shows that the proxy authentication negotiation is ...
      (microsoft.public.dotnet.distributed_apps)
    • Re: eap-tls and peap-tls
      ... Certificate revocation is NOT designed as a user control mechanism, ... We have all the authentication working perfectly using> eap-tls, we're now testing the certificate revocation for the opps> people. ... Should the IAS server check for> revocation list as set on the CA schedule? ...
      (microsoft.public.internet.radius)
    • Re: Certificate Services
      ... Check that your server trusts all parent CAs. ... > "The revocation function was unable to check revocation ... > verify the current CA certificate. ...
      (microsoft.public.windows.server.networking)
    • SSLCARevocationFile
      ... I built a web server with apache 2.xx. ... the certificate has been well revocated and is part of the CRL with the ... Revocation Date: Mar 17 13:13:21 2006 GMT ...
      (comp.infosystems.www.servers.unix)
    • Re: Smart Card Logon Failure with Windows 2003 Server (works with Windows 2000 server)
      ... certificate could not be validated because the revocation ... The error message from the event log on the CDC is in the ... revocation function was unable to check revocation because ... >> the CRL is downloaded. ...
      (microsoft.public.win2000.security)

    Loading