Re: IIS 6 behavior on checking clients' certificates (again)

From: Brian Komar [MVP] (bkomar_at_nospam.identit.ca)
Date: 09/19/05


Date: Mon, 19 Sep 2005 09:26:51 -0500

In article <10396707-61B4-46C6-9C74-5B2CD990C6EB@microsoft.com>,
Vsevolod@discussions.microsoft.com says...
> Hello !
>
> "Brian Komar [MVP]" wrote:
> > CRL checking is not enabled by default on IIS 5.0, if I remember correctly, while > it is enforced on IIS 6.0.
>
> Could I turn off or disable CRL checking on IIS 6.0 ?
>
> BR,
> Vsevolod.
>
Why would you even consider turning of CRL checking?!?!?!?!?

You are taking the chance of using a revoked certificate! Fix your delta
CRL publication issue instead.

Brian



Relevant Pages

  • Re: IIS 6 behavior on checking clients certificates (again)
    ... >> Why would you even consider turning of CRL checking?!?!?!?!? ... > I'm not taking the chance of using a revoked certificate because ... If you are using OCSP, then the AIA extension would have the OCSP ...
    (microsoft.public.windows.server.security)
  • Re: Keeping expired certificates in CRLs
    ... A revoked certificate will be removed from the CRL ... > one CRL publishing period beyond the validity period of the certificate. ...
    (microsoft.public.windows.server.security)
  • Re: User can logon after certificate is revoked
    ... If the DC's have the old CRL cached, they will use that until the old CRL ... > We have set the user to require a smart card for logon. ... > The user can still logon with the revoked certificate on ... > CRL publishing is set for 1 hour. ...
    (microsoft.public.win2000.security)
  • Re: Using a CRL
    ... Are you sure the web server cert is revoked and on the CRL? ... > particular client from making a secure connection ... > to the web server whose revoked certificate is indicated ...
    (microsoft.public.security)
  • Re: Windows doesnt verify digital signature of CRL files
    ... > LDAP/HTTP CRL download, and CAPI is not validating signatures on CRL's ... > then a person could use a revoked certificate for access to systems among ... the verification process. ... So unless you're using Microsoft's CryptoAPI at a low level and you ...
    (Bugtraq)