import crl from server in other (trusted) domain


hi,

we migrating system downloads crl , imports ad. original system in same domain domain controller publishing crl to. published crl following command

certutil -dspublish -f filename dc.domaina.corp

however, on our new system, in domainb.corp,  when download crl , try import in domaina.corp, same command, following output

----------------------------------
ldap:///cn=mycompany private ca,cn=dc.domaina,cn=cdp,cn=public key services,cn=services,cn=configuration,dc=domainb,dc=corp?certificaterevocationlist

ldap: 0x20: 0000208d: nameerr: dsid-031001cd, problem 2001 (no_object), data 0, best match of:
 'cn=cdp,cn=public key services,cn=services,cn=configuration,dc=domainb,dc=corp'

certutil: -dspublish command failed: 0x8007208d (win32: 8333)
certutil: directory object not found.
--------------------

somehow, ldap command takes suffix domainb.corp integrate in command.

i read through certutil commands, absolute not expert on certificates. can telle me if thing want possible? maybe switch

you have 2 different forests. actual publication location the forest root domain, , issue, obvious in separate forest scenario.
i recommend switching using http based urls rather ldap ad-based urls environment
brian


Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2