Click here to get back home

Publishing offline root in AD and AIA and capolicy.inf

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Publishing offline root in AD and AIA and capolicy.inf NothingtoSay? 07-12-2005
Posted by NothingtoSay? on July 12, 2005, 11:26 pm
Please log in for more thread options
Hi all,

situation is this :-
2003 member servers pre SP1
offline root CA
enterprise issuing CA in my domain x.y.net

Ive used capolicy.inf to modify offline root CA settings as follows
================================
[Version]
Signature= "$Windows NT$"

[CAPolicy]
Policies=LegalPolicy

[LegalPolicy]
OID=1.1.1.1.1.1.1.1.1
URL="http://mycompany/capolicy.htm"
Notice = "LEgal text"

[CRLDistributionPoint]
URL = ""

[AuthorityInformationAccess]
URL = ""
================================

main reason for this (i know its not a valid oid) was to remove need to
check root ca crl and to add a legal notice.

I want to publish offline root CA cert into my company AD but am unsure
if i can do this if AIA setting doesnt show a valid LDAP path? (ie to a
point within my AD)

Where i also get confused is do i have to set the AIA to point to my AD
domain in capolicy.inf or can i do this by modifying the extensions tab
of the CA once its installed (if its actually required at all ?)

Command i would use for publishing cert into AD was
certutil.exe -dspublish

Additionally what is the feeling about removing root Crl entry as ive
done in capolicy.inf?

Many thanks
Jonathan



Similar ThreadsPosted
Offline Root CA and CDP/AIA paths August 29, 2005, 8:26 am
Offline Root CA CDP Expiring April 26, 2006, 2:46 am
Publish Offline Root CRL June 3, 2008, 12:07 pm
Offline CA Root certificate invisble in AD March 21, 2007, 3:48 pm
PKI - Single Offline Root for Multiple Forest March 24, 2008, 9:02 pm
publishing the CRL July 6, 2005, 1:33 pm
Certificate autoenrollment and AD publishing July 24, 2008, 9:15 am
Whats wrong with my CAPolicy.inf file? July 6, 2006, 3:35 am
use of Issuance policy in capolicy.inf file January 19, 2008, 5:54 pm
Migrate Enterprise root authority CA to stand-alone root CA December 13, 2005, 7:57 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap