|
Posted by Pedro on July 4, 2006, 3:11 pm
Please log in for more thread options
Hi
I have problem with my CA. When I renew CA certificate (new KEY is
generate) on my SUB-CA (request issuing by OFFLINE ROOT-CA) and
installing new certificate on SUB-CA (SUB-CA is AD's member) and
publicate new CRL in "Active Directory Sites and Services" is create
new object:
AD Sites and Services\Configuration\Services\Public Key
Services\CDP\SUB-CA(1) but is not create
object: AD Sites and Services\Configuration\Services\Public Key
Services\AIA\SUB-CA(1).
My LDAP path for CDP distribution point:
ldp:///CN=SUB-CA(1),CN=CDP,CN=Public Key
Services,CN=Services,CN=Configuration,DC=company,DC=com?certificateRevocationList?base?objectClass=cRLDistributionPoint
WORKING OK
but
LDP for AIA: ldap:///CN=SUB-CA(1),CN=AIA,CN=Public Key
Services,CN=Services,CN=Configuration,DC=company,DC=com NOT WORKING
because AD haven't CertyficationObject SUB-CA(1)
What is wrong ?? Why AD don't create SUB-CA(1) in container AIA ?
P.
|