Problem with CDP Locations
hello,
i experiencing issue. setup follows:
offline root ca
enterprise issuing subca
recently attempting set eap-tls wired network test. ran radius error code 259. said crl not verified.
i ran pkiview.msc , get:
cdp location #1 expired ldap:///cn=openxcorpca,cn=openxcorpca,cn=cdp,cn=public%20key%20services,cn=services,cn=configuration,dc=corp,dc=openx,dc=com?certificaterevocationlist?base?objectclass=crldistributionpoint
cdp location #2 unable download http://ca-cert-01/certenroll/%3ccaname%3e.crl
location #1 offline root ca
location #2 issuing enterprise subca.
i attempted location #2 , error. when use following url crl.
http://ca-cert-01/certenroll/ca-cert-01.crl
my question is #3ccaname%3e.crl incorrect? how change it?
thank you,
akash
that incorrect name. have lot of other expired stuff. problem can't tell server - ca-cert-01 subordinate or root? screenshot of pkiview.msc expanded or can use following command on radius server against certificate there.
certutil -urlfetch -verify <certificate>
mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years.
Windows Server > Security
Comments
Post a Comment