AIA verification fails while using certutil utility for a certificate


when try certutil -url <certname.cer>

crl , ocsp verification successful , while retrieving aia
following error "revocation check failed" , verified url (both http , ldap-dint edit part) , i'm able download ca certificate
using url listed in aia .
reasons why fails

you have several expired crls:

expired "base crl (11)" time: 0
    [2.0] http://onlineresponder.abcpki.com/certenroll/abcindsubca.crl
not correctly copying updated crl referenced server. first 1 not issue, because of cdp locations time valid

your big problem @ root ca. of crls expired. failure occurring in validation of subca certificate. not expired, different versions exist in ad versus subca folder.

  expired "base crl (3)" time: 0
    [0.0] ldap:///cn=abcca,cn=certauth,cn=cdp,cn=public%20key%20services,cn=services,cn=configuration,dc=abcpki,dc=com?certificaterevocationlist?base?objectclass=crldistributionpoint

  expired "base crl (5)" time: 0
    [1.0] http://subca/certenroll/abcca.crl

you need spend time on ensuring correct publication taking place (start @ root ca , work down) , correct version published *all* referenced publication points

brian



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group