Click here to get back home

Issuer Statement is not available

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Issuer Statement is not available MarkAlexander 09-13-2006
Posted by MarkAlexander on September 13, 2006, 11:39 am
Please log in for more thread options

We can't seem to make the Issuer Statement available even though we are
placing the capolicy.inf in the windows folder prior to installing a new root
ca. We have tried multiple versions of the file including the one in "Windows
Server 2003 PKI Certificate Security". The below example below is the latest
based on Berkeley's capolicy.inf. The actual URL is valid but not shown
below. Other items like CRLPeriodUnits process ok and show up in issued
certs. Certmmc.log shows no syntax errors etc.

Any ideas?

--
Mark

[Version]

Signature="$Windows NT$"



[CAPolicy]

Policies=LegalPolicy1



[LegalPolicy1]

OID=1.3.6.1.4.1.4995.1000.2.1.1.2

URL = “http://www.xxxx.com/xxxCPS.html"

Notice = “Legal policy statement text."



[certsrv_server]

Renewalkeylength=4096

RenewalValidityPeriodUnits=10

RenewalValidityPeriod=years



CRLPeriod=weeks

CRLPeriodUnits=37

CRLDeltaPeriodUnits=0

CRLDeltaPeriod=days



[CRLDistributionPoint]

Empty=True



[AuthorityInformationAccess]

Empty=True



[BasicConstraintsExtension]

PathLength=4




--
Mark

Posted by Brian Komar [MVP] on September 13, 2006, 6:12 pm
Please log in for more thread options
MarkAlexander@discussions.microsoft.com says...
> the windows folder prior to installing a new root
> ca. We have tried multiple versions of the file including the one in "Windows
> Server 2003 PKI Certificate Security". The below example below is the latest
> based on Berkeley's capolicy.inf. The actual URL is valid but not shown
> below. Other items like CRLPeriodUnits process ok and show up in issued
> certs. Certmmc.log shows no syntax errors etc.
>
If you copied and pasted directly out of the book (off the CD), then you
probably have the
incorrect quotes around the url and the notice text. Make sure that you are
using the "
character and not the separate left double quote and right double quote
characters.

Brian

Posted by MarkAlexander on September 13, 2006, 6:30 pm
Please log in for more thread options
Thanks Brian,

We found the correct example for 2003 syntax on page 517 and that worked. We
used that example OID too, but are not sure what it means in that context.
Any comment?

Thanks again!
--
Mark


"Brian Komar [MVP]" wrote:

> MarkAlexander@discussions.microsoft.com says...
> > the windows folder prior to installing a new root
> > ca. We have tried multiple versions of the file including the one in
"Windows
> > Server 2003 PKI Certificate Security". The below example below is the
latest
> > based on Berkeley's capolicy.inf. The actual URL is valid but not shown
> > below. Other items like CRLPeriodUnits process ok and show up in issued
> > certs. Certmmc.log shows no syntax errors etc.
> >
> If you copied and pasted directly out of the book (off the CD), then you
probably have the
> incorrect quotes around the url and the notice text. Make sure that you are
using the "
> character and not the separate left double quote and right double quote
characters.
>
> Brian
>

Posted by Brian Komar [MVP] on September 13, 2006, 9:29 pm
Please log in for more thread options
MarkAlexander@discussions.microsoft.com says...
> und the correct example for 2003 syntax on page 517 and that worked. We
> used that example OID too, but are not sure what it means in that context.
> Any comment?
>
You need to acquire an enteprise OID arc for your own organization.
CHeck out the index for details on how to acquire an Arc.
Brian

Posted by MarkAlexander on September 13, 2006, 10:57 pm
Please log in for more thread options

Will do, thanks Brian!
--
Mark


"Brian Komar [MVP]" wrote:

> MarkAlexander@discussions.microsoft.com says...
> > und the correct example for 2003 syntax on page 517 and that worked. We
> > used that example OID too, but are not sure what it means in that context.
> > Any comment?
> >
> You need to acquire an enteprise OID arc for your own organization.
> CHeck out the index for details on how to acquire an Arc.
> Brian
>

Similar ThreadsPosted
Issuer Statement does not appear in user certs October 4, 2006, 4:52 pm
Enabling the Issuer Statement button on Issued Certificates January 16, 2008, 9:24 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap