Click here to get back home

Issuer Statement does not appear in user certs

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Issuer Statement does not appear in user certs MarkAlexander 10-04-2006
Posted by MarkAlexander on October 4, 2006, 4:52 pm
Please log in for more thread options

It did appear in the root and issuing CA certs, but not in subsequent user
certs.

Note that we used the forest guid tip on page 98 of "Microsoft Windows
Server 2003 PKI and Certificate Security" to generate our own OID for the
issuer statement.

Below is the issuing CA capolicy.inf.

We are pretty stuck.

Thanks!

--
Mark

[Version]
Signature="$Windows NT$"

[PolicyStatementExtension]
Policies=LegalPolicy

[LegalPolicy]
OID=1.3.1.4.1.311.21.8.12764945.5603197.11616931.5177453.16042184.1.402
URL = http://www.xrce.xerox.com/xlpki/CPS/XeroxlabsCPS.html
Notice = Xeroxlabs Legal policy statement text

[certsrv_server]
keylength=4096
ValidityPeriod=Years
ValidityPeriodUnits=20

CRLPeriod=weeks
CRLPeriodUnits=33
CRLDeltaPeriodUnits=0
CRLDeltaPeriod=days

[CRLDistributionPoint]
URL=ldap:///CN=naca4,CN=naca,CN=CDP,CN=Public Key
Services,CN=Services,CN=Configuration,DC=XLPKI,DC=com?certificateRevocationList?base?objectClass=cRLDistributionPoint
URL=http://naca.xlpki.com/CertEnroll/naca4.crl

URL = http://www.xrce.xerox.com/xlpki/CertEnroll/naca4.crl

[AuthorityInformationAccess]
URL=ldap:///CN=naca4,CN=AIA,CN=Public Key
Services,CN=Services,CN=Configuration,DC=XLPKI,DC=com?cACertificate?base?objectClass=certificationAuthority
URL=http://naca.xlpki.com/CertEnroll/naca.xlpki.com_naca4.crt
URL=http://www.xrce.xerox.com/xlpki/CertEnroll/naca.xlpki.com_naca4.crt

[BasicConstraintsExtension]
PathLength=4

Similar ThreadsPosted
Issuer Statement is not available September 13, 2006, 11:39 am
Enabling the Issuer Statement button on Issued Certificates January 16, 2008, 9:24 am
Child domain laptops autoenrolling user certs but not computer certs May 21, 2008, 4:19 pm
Problem with Machine Certs being used as User Certs June 15, 2005, 7:06 am
Self-signed certs for FTP October 10, 2006, 7:07 pm
CA configuration to publish certs in AD October 2, 2006, 9:42 am
GPO for trusted root CA certs November 7, 2006, 8:12 am
Certs in non-domain environment: January 24, 2008, 12:51 pm
Auto-renewing certs w/ VPN clients February 15, 2006, 9:44 am
IPSec certs vs shared secret September 23, 2006, 8:06 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap