Click here to get back home

PKI revocation questions...

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
PKI revocation questions... snickered 09-10-2008
Get Chitika Premium
Posted by snickered on September 10, 2008, 9:18 am
Please log in for more thread options


I have been trying to get my computers to delete revocated
certificates for about a week and haven't been successful. I have a
couple of questions.

1. How does the client know when to check for a new CRL? I know that
it's as long as the CRL is valid but how do I determine that? Also,
when I delete my urlcache with 'certutil -urlcache * delete' and then
do 'certutil -pulse' the cache isn't updated.

2. With that in mind how do I get manually get my client computers to
check for revoked certificates that have been issued to that
computer? I have tried 'gpupdate /target:computer' and 'certutil -
pulse' but neither seem to be doing the trick.

I will name my kid after you if you can answer my questions... I have
spent waaaay too much time on this thing. TIA.

Posted by Brian Komar \(MVP\) on September 10, 2008, 11:14 am
Please log in for more thread options


What client OS and what CA OS are you working with?
Brian

>I have been trying to get my computers to delete revocated
> certificates for about a week and haven't been successful. I have a
> couple of questions.
>
> 1. How does the client know when to check for a new CRL? I know that
> it's as long as the CRL is valid but how do I determine that? Also,
> when I delete my urlcache with 'certutil -urlcache * delete' and then
> do 'certutil -pulse' the cache isn't updated.
>
> 2. With that in mind how do I get manually get my client computers to
> check for revoked certificates that have been issued to that
> computer? I have tried 'gpupdate /target:computer' and 'certutil -
> pulse' but neither seem to be doing the trick.
>
> I will name my kid after you if you can answer my questions... I have
> spent waaaay too much time on this thing. TIA.


Posted by snickered on September 10, 2008, 7:20 pm
Please log in for more thread options


On Sep 10, 10:14=A0am, "Brian Komar \(MVP\)"
> What client OS and what CA OS are you working with?
> Brian
>
>
>
> >I have been trying to get my computers to delete revocated
> > certificates for about a week and haven't been successful. =A0I have a
> > couple of questions.
>
> > 1. =A0How does the client know when to check for a new CRL? =A0I know t=
hat
> > it's as long as the CRL is valid but how do I determine that? =A0Also,
> > when I delete my urlcache with 'certutil -urlcache * delete' and then
> > do 'certutil -pulse' the cache isn't updated.
>
> > 2. =A0With that in mind how do I get manually get my client computers t=
o
> > check for revoked certificates that have been issued to that
> > computer? =A0I have tried 'gpupdate /target:computer' and 'certutil -
> > pulse' but neither seem to be doing the trick.
>
> > I will name my kid after you if you can answer my questions... I have
> > spent waaaay too much time on this thing. =A0TIA.

The famous Brian!! Love your book. I am working with 2008 as my CA
(followed your setup in ch. 6) and 2003/Vista as the clients.

Similar ThreadsPosted
Revocation server was offline March 26, 2006, 10:25 pm
2008 CA revocation/autoenrollment process... September 5, 2008, 4:28 pm
Certificates trouble: CRL not available(?) and "revocation server offline" error April 29, 2007, 2:05 pm
Wired 802.1x Questions May 1, 2006, 3:30 pm
Questions about CDP an AIA distribution points July 11, 2006, 7:41 am
antivirus software questions September 19, 2006, 2:25 pm
Active Directory Questions. November 24, 2006, 12:09 am
Questions about using IPsec across domains February 25, 2008, 5:47 pm
Security Questions and Answers for CLM April 29, 2008, 3:31 am
Several questions on code signing / smartcards / Win CA August 25, 2005, 4:24 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap