Networking Forums

Networking Forums > Computer Networking > Windows Networking > Certificates

Reply
 
 
Dumb Luck
Guest
Posts: n/a

 
      03-22-2007, 03:04 PM
I am having issues creating a subordinate CA.

Here is the situation, I have an Enterprise CA for the domain, and I
am trying to create a subordinate CA that is not connected on the
domain. I request a cert and issue the cert from the Root CA. I
install everything and it all looks to be working fine. Then I open
Certificate Authority msc and try to start the services and it says
that the CRL can not be found. I can ping the Root CA using the
certutil command. I can browse to the crl using http, I can also
connect using telnet on port 3890. Why can't the subordinate CA
retrieve the CRL?

Thanks in advance for any assistance.
Trevor

 
Reply With Quote
 
 
 
 
Nick Domukhovsky
Guest
Posts: n/a

 
      03-23-2007, 05:28 AM
> I am having issues creating a subordinate CA.
>
> Here is the situation, I have an Enterprise CA for the domain, and I
> am trying to create a subordinate CA that is not connected on the
> domain. I request a cert and issue the cert from the Root CA. I
> install everything and it all looks to be working fine. Then I open
> Certificate Authority msc and try to start the services and it says
> that the CRL can not be found. I can ping the Root CA using the
> certutil command. I can browse to the crl using http, I can also
> connect using telnet on port 3890. Why can't the subordinate CA
> retrieve the CRL?
>
> Thanks in advance for any assistance.
> Trevor
>

1). Make sure, that LDAP URL listed in CDPs is available from your
subordinate CA (so there is no name resolution problems).
2). Make crl readable by everyone (including anonymous users). You can
use various LDAP browsers to check availability of the crl (for example,
Softerra LDAP Browser - http://download.softerra.com/files/ldapbrowser26.msi



--
With best regards
Nickolay Domukhovsky, MCSA
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN with Certificates SuperPlay Windows Networking 0 06-13-2007 02:04 PM
PLEASE HELP ! L2TP & Certificates jlathamjr@gmail.com Windows Networking 0 09-15-2006 07:24 PM
VPN and Certificates SeanB Windows Networking 0 09-08-2005 10:31 AM
PEAP and Certificates Jobe Gates Wireless Networks 2 06-15-2005 12:51 PM
L2TP certificates William King Windows Networking 0 06-25-2004 12:11 PM



1 2 3 4 5 6 7 8 9 10 11