Click here to get back home

pki - certificate problems

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
pki - certificate problems render 06-06-2006
Get Chitika Premium
Posted by render on June 6, 2006, 11:02 am
Please log in for more thread options
Hi!



i setup an pki like described in the article "publishing a public key
infrastructure with isa server 2004"
(http://www.isaserver.org/tutorials/Publishing-Public-Key-Infrastructure-ISA-Server-2004-Part3.html).
everything was fine but when i configured the issuing ca i mistyped the
http-location for the AIA. instead the fileextension crt i used crl. when i
use the pkiview.msc from the w2k3 resourcekit tools i can see the error.


see image: http://www.dvg-gmbh.de/supporttemp/isa/pkiview.jpg


i corrected the entry in the settings from my issuing ca and issued new
domain controller certificates but the error stays the same.

now i need help how to figure out where else i have to make modifications.

thanks

render

Posted by bagins on June 6, 2006, 7:25 pm
Please log in for more thread options
What do you see in AIA field of issued (new) certificate? Is the url OK? If
it is, IMHO, you should not worry about PkiView (someone, correct me if I am
wrong, please).
Also, you can try something like this:
Use certutil -view to find the problematic url. Note the Row ID in the
output.
Try using certutil -deleterow RowID, to remove the old url.
Be careful, you can easely delete more than you would like.

--

************************
Best regards
Bagins
************************


> Hi!
>
>
>
> i setup an pki like described in the article "publishing a public key
> infrastructure with isa server 2004"
> (http://www.isaserver.org/tutorials/Publishing-Public-Key-Infrastructure-ISA-Server-2004-Part3.html).
> everything was fine but when i configured the issuing ca i mistyped the
> http-location for the AIA. instead the fileextension crt i used crl. when
> i
> use the pkiview.msc from the w2k3 resourcekit tools i can see the error.
>
>
> see image: http://www.dvg-gmbh.de/supporttemp/isa/pkiview.jpg
>
>
> i corrected the entry in the settings from my issuing ca and issued new
> domain controller certificates but the error stays the same.
>
> now i need help how to figure out where else i have to make modifications.
>
> thanks
>
> render



Posted by render on June 14, 2006, 6:53 am
Please log in for more thread options
i issued a new certificate and there the AIA is ok. everything works fine now
so i ignore the pkiview status.

thanks a lot.

render


"bagins" schrieb:

> What do you see in AIA field of issued (new) certificate? Is the url OK? If
> it is, IMHO, you should not worry about PkiView (someone, correct me if I am
> wrong, please).
> Also, you can try something like this:
> Use certutil -view to find the problematic url. Note the Row ID in the
> output.
> Try using certutil -deleterow RowID, to remove the old url.
> Be careful, you can easely delete more than you would like.
>
> --
>
> ************************
> Best regards
> Bagins
> ************************
>
>
> > Hi!
> >
> >
> >
> > i setup an pki like described in the article "publishing a public key
> > infrastructure with isa server 2004"
> > (http://www.isaserver.org/tutorials/Publishing-Public-Key-Infrastructure-ISA-Server-2004-Part3.html).
> > everything was fine but when i configured the issuing ca i mistyped the
> > http-location for the AIA. instead the fileextension crt i used crl. when
> > i
> > use the pkiview.msc from the w2k3 resourcekit tools i can see the error.
> >
> >
> > see image: http://www.dvg-gmbh.de/supporttemp/isa/pkiview.jpg
> >
> >
> > i corrected the entry in the settings from my issuing ca and issued new
> > domain controller certificates but the error stays the same.
> >
> > now i need help how to figure out where else i have to make modifications.
> >
> > thanks
> >
> > render
>
>
>

Similar ThreadsPosted
Automatic Certificate Enrollment Problems April 5, 2006, 11:45 am
Problems setting up automatic certificate requests July 25, 2005, 8:39 am
EFS problems January 4, 2007, 2:15 pm
Ca problems February 2, 2007, 3:59 am
Problems with a CA restore help... July 5, 2006, 10:58 am
Problems with Enterprise CA July 14, 2006, 4:39 am
Problems with NTP on Win2003 February 21, 2007, 11:00 am
Problems logging to server December 21, 2005, 1:07 pm
Problems With Kerberos Authentication September 25, 2007, 2:33 am
FTP site on ADC creating problems!!!! June 21, 2008, 11:49 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap