AIA verification fails while using certutil utility for a certificate
crl , ocsp verification successful , while retrieving aia
following error "revocation check failed" , verified url (both http , ldap-dint edit part) , i'm able download ca certificate
using url listed in aia .
reasons why fails
you have several expired crls:
expired "base crl (11)" time: 0
[2.0] http://onlineresponder.abcpki.com/certenroll/abcindsubca.crl
not correctly copying updated crl referenced server. first 1 not issue, because of cdp locations time valid
your big problem @ root ca. of crls expired. failure occurring in validation of subca certificate. not expired, different versions exist in ad versus subca folder.
expired "base crl (3)" time: 0
[0.0] ldap:///cn=abcca,cn=certauth,cn=cdp,cn=public%20key%20services,cn=services,cn=configuration,dc=abcpki,dc=com?certificaterevocationlist?base?objectclass=crldistributionpoint
expired "base crl (5)" time: 0
[1.0] http://subca/certenroll/abcca.crl
you need spend time on ensuring correct publication taking place (start @ root ca , work down) , correct version published *all* referenced publication points
brian
Windows Server > Security
Comments
Post a Comment