Click here to get back home

publishing the CRL

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
publishing the CRL Paul Bergson 07-06-2005
Get Chitika Premium
Posted by Paul Bergson on July 6, 2005, 1:33 pm
Please log in for more thread options
Unclear as to how the CRL gets updated at the CDP? Is this something we
have to manually do? From everything I have read it is a manual process.

Do sites script the CDP update process if it is manual?

--

Thanks

Paul Bergson




Posted by Steven L Umbach on July 7, 2005, 1:55 am
Please log in for more thread options
It can and often is done automatically particularly if default CDP are used
and the CA is online such as for an Enterprise CA on a domain network. If
you have any "offline" CA's however you would need to do this manually. If
you are using Windows 2003 you can use the PKI Health Tool to check the
status of your CRL's. The second link below would be a good start to
troubleshooting CRL's and learning more about them. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;295663 --- see
Method 1 for more info on PKI Health Tool.
http://www.microsoft.com/technet/security/topics/cryptographyetc/tshtcrl.mspx


> Unclear as to how the CRL gets updated at the CDP? Is this something we
> have to manually do? From everything I have read it is a manual process.
>
> Do sites script the CDP update process if it is manual?
>
> --
>
> Thanks
>
> Paul Bergson
>




Posted by Paul Adare on July 7, 2005, 8:33 am
Please log in for more thread options
microsoft.public.windows.server.security news group, Paul Bergson

> Unclear as to how the CRL gets updated at the CDP? Is this something we
> have to manually do? From everything I have read it is a manual process.
>
> Do sites script the CDP update process if it is manual?
>

This depends on what you're using for hosting your CDP. If you're using
Actice Directory and your CAs are Enterprise CAs they will be published
automatically. If you're using HTTP and you're using the CAs themselves
as the web servers hosting the CDPs as long as you configure the CDP
location to point to the folder where the CRLs are published to the
files system (WINDOWS\system32\CertSrv\CertEnroll by default) the
publication is automatic.
For most other locations, and for offline CAs, the publication is a
manual process and yes, it is normally scripted with a scheduled task.

--
Paul Adare
MVP - Windows - Virtual Machine
http://www.identit.ca/blogs/paul/
"The English language, complete with irony, satire, and sarcasm, has
survived for centuries without smileys. Only the new crop of modern
computer geeks finds it impossible to detect a joke that is not clearly
labeled as such."
Ray Shea


Posted by Paul Bergson on July 7, 2005, 7:43 am
Please log in for more thread options
I guess I forgot to include all info. We are publishing internally and
externally (External is aliased). I'm looking to change to external (DMZ)
only and change the certs to point to this and hopefully get the ECA to push
directly to the external web site.

For now we are running a scheduled task to push externally. It is a cya
site since we set the PKI years ago and at the time we didn't need the
external certs but now that we have started to use them externally our
clients needed access to the cdp.

--
Thanks

Paul Bergson




> microsoft.public.windows.server.security news group, Paul Bergson
>
>> Unclear as to how the CRL gets updated at the CDP? Is this something we
>> have to manually do? From everything I have read it is a manual process.
>>
>> Do sites script the CDP update process if it is manual?
>>
>
> This depends on what you're using for hosting your CDP. If you're using
> Actice Directory and your CAs are Enterprise CAs they will be published
> automatically. If you're using HTTP and you're using the CAs themselves
> as the web servers hosting the CDPs as long as you configure the CDP
> location to point to the folder where the CRLs are published to the
> files system (WINDOWS\system32\CertSrv\CertEnroll by default) the
> publication is automatic.
> For most other locations, and for offline CAs, the publication is a
> manual process and yes, it is normally scripted with a scheduled task.
>
> --
> Paul Adare
> MVP - Windows - Virtual Machine
> http://www.identit.ca/blogs/paul/
> "The English language, complete with irony, satire, and sarcasm, has
> survived for centuries without smileys. Only the new crop of modern
> computer geeks finds it impossible to detect a joke that is not clearly
> labeled as such."
> Ray Shea




Similar ThreadsPosted
Certificate autoenrollment and AD publishing July 24, 2008, 9:15 am
Publishing offline root in AD and AIA and capolicy.inf July 12, 2005, 11:26 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap