CDP and DeltaCRL locations unable to download


i want apologize ahead of time. first time posting tread.

i having problems getting pki display status ok locations. running windows enterprise , windows 7 professional on clients.

 my ldap:/// locations ok cdp & deltacrl locations status unable download. actual errors listed as

deltacrl location #2      unable download         http:/scsihq-dc01.corp-hq.scsi-ga.com/certenroll//corp-hq-scsihq-dc01-ca(1)+.crl

deltacrl location #3      unable download         file://scsihq-dc01.corp-hq-ga.com/certenroll//corp-hq-scsihq-dc01-ca(1)+.crl

cdp location #2             unable download         http:/scsihq-dc01.corp-hq.scsi-ga.com/certenroll//corp-hq-scsihq-dc01-ca(1).crl

cdp location #3             unable download         file://scsihq-dc01.corp-hq-ga.com/certenroll//corp-hq-scsihq-dc01-ca(1).crl

things have done:

- have set vaule true double spacing in iis7 , have restarted , no luck

- have renewed ca certificate , when did have (2) ca. certificate #0 (old) , certificate #1 (new) showing under ca properties #1 1 listed active ca on server.

- have changed extensions under ca properties , still unable rid of errors.

- error when try past url in browser , go site. message showing url address , physical address , different.

 deltacrl location #2 

requested url http://scsihq-dc01.corp-hq.scsi-ga.com:80/certenroll/corp-hq-scsihq-dc01-ca(1)+.crl
physical path

c:\inetpub\wwwroot\certenroll\corp-hq-scsihq-dc01-ca(1)+.crl

cdp location #2

 

requested url http://scsihq-dc01.corp-hq.scsi-ga.com:80/certenroll/corp-hq-scsihq-dc01-ca(1).crl
physical path c:\inetpub\wwwroot\certenroll\corp-hq-scsihq-dc01-ca(1).crl

i have gone these physical path , there nothing in these locations.

- have read post on cdp location unableto download , numerous ones there aftere , still no luck.

- have went , re-installes online responder , pki step step. ad cs step step , online responder trouble shooting.

i have went actual folder locations ato verify vdir , file locations. third cdp , deltacrl location did not appear in config until after had renewed ca. thinking on kill pki , need 2 locations. 

i appreciate anysite can offer me resolve these issues.

i have few more issues talke 1 @ time.

 

thank you

when cdp paths working correctly, browser attempt download file when use url.  recommend use ie verify crl downloadable.

i typically use different web site and/or machine when publish cdp because might want offload onto machine or make accessible outside environment.

if point deltas not work, check double escaping feature of website in iis.

hth - fr3dd


fr3dd


Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

difference between wuauclt1.exe and wuauclt.exe

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL