Click here to get back home

fail to contact windows 2003 LDAP server to retrive new CRL.

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
fail to contact windows 2003 LDAP server to retrive new CRL. Mr555 08-22-2006
Posted by Mr555 on August 22, 2006, 6:11 pm
Please log in for more thread options
3 months ago we migrated to windows 2003 Server.

We have moved the entire FSMO role from our old windows 2000 server “Corp”
to our new windows 2003 Server “Paul” Paul is now the forest root of our
network.
The ip address of Paul is 192.168.1.2

Few weeks ago our windows 2000 certificate server "Spoon" die, we decided to
rebuild the certificate server to windows 2003. The new certificate server is
now called "Mugen" and is configured as a stand-alone root CA member server.
The purpose of this certificate server is to authenticate VPN connection to
our network and is operate together with our netscreen VPN / firewall.

15 days ago, our VPN / firewall failing to retrieve CRL from certificate
server. Therefore VPN connections stop working.

Under extensive investigation, I have discovered we can only make our
VPN/firewll to automatically obtain CRL from the certificate server “Mugen” ,
if we specific the old LDAP server IP address “ corp.” which is 192.168.1.1,

if I enter the ip address of Paul 192.168.1.2 to the VPN/ firewall
certificate settings, the automatic CRL retrieve will fail.

I have checked with the firewall support team. They said netscreen does
support windows 2003 Server. They suspect I have not configured our
certificate server correctly to work under “Paul” LDAP Server.

Questions:

Are there any configuration or security policy I need to configure to allow
communication between LDAP “Paul” server and certificate server “ Mugen”?

I need to specific “Paul” as the LDAP server on the VPN setup instead of corp.
Server, please help

Thank you

Mr555




Similar ThreadsPosted
failing to retrive CRL from certificate server using new LDAP Serv August 22, 2006, 6:12 pm
Microsoft Server 2003 LDAP Cert and CRL access by Router November 21, 2005, 8:21 am
Windows 2008 CA can't issue to Windows 2003 server June 25, 2008, 11:53 am
Windows server 2003 security. How to protect against 100's of invalid logons to the server?? August 12, 2005, 5:29 pm
Windows server 2003 and Windows SBS Cost ? August 25, 2005, 11:19 pm
SP-1 to a Windows 2003 Server running SQL Server 2000 with out SP- July 5, 2005, 5:20 pm
no server credential/no LDAP over SSL June 17, 2005, 3:24 pm
VPN and Windows 2003 Server May 31, 2005, 11:58 pm
Windows Server 2003 R2 March 10, 2007, 10:20 am
Windows 2003 Server SP2 April 9, 2008, 5:03 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap