Enterprise subordinate CA cannot publish to http location: "the directory name is invalid. 0x8007010b (WIN32/HTTP: 267)"


enterprise subordinate ca cannot publish http location in certificate extensions. guessing iis issue. i not sure why happening becuase iis working fine otherwise , pkiview shows no issue downloading crl , crts manually published to http location, when try publish new crl message:

"the directory name invalid. 0x8007010b (win32/http: 267)"

i should enterprise subordinate ca acting webserver hosting certs maybe there conflict between default certsvr website , cdp distribution site?

publishing works default extensions prior adding extensions in script:

::declare configuration nc
certutil -setreg ca\dsconfigdn cn=configuration,dc=lab,dc=com

::define crl publication intervals
certutil -setreg ca\crlperiodunits 3
certutil -setreg ca\crlperiod "days"
certutil -setreg ca\crldeltaperiodunits 12
certutil -setreg ca\crldeltaperiod "hours"

::apply required cdp extension urls
certutil -setreg ca\crlpublicationurls "65:%systemdrive%\certenroll\%%3%%8%%9.crl\n79:ldap:///cn=%%7%%8,cn=%%2,cn=cdp,cn=public key services,cn=services,%%6%%10\n6:http://cdp.lab.com/certdata/%%3%%8%%9.crl"

::apply required aia extension urls
certutil -setreg ca\cacertpublicationurls "1:%systemdrive%\certenroll\%%1_%%3%%4.crt\n3:ldap:///cn=%%7,cn=aia,cn=public key services,cn=services,%%6%%11\n2:http://cdp.lab.com/certdata/%%1_%%3%%4.crt\n0:file://\\%%1\certenroll/%%1_%%3%%4.crt"

::enable auditing events lab corporate policy ca
certutil -setreg ca\auditfilter 127

::set validity period issued certificates
certutil -setreg ca\validityperiodunits 2
certutil -setreg ca\validityperiod "years"



thanks responses.

hi

have created directory %systemdrive%\certenroll? think proper path should %windir%\system32\certsrv\certenroll.

best regards

martin rublik


Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group