Enterprise PKI - all http locations Unable To Download


first off servers 2008r2 (latest updates installed) w/forest-domain 2008r2, cas (rca, sca) installed on dcs vms (hyperv 2008r2).  utilize scm 2.5 gpo settings on dcs (don't know if potential issues due security settings?).

initially set w/out issue , ran fine.  poking around server yesterday , noticed have errors showing on enterprise pki. 

sca has following unable download errors showing:

aia location #2  http://wwwca/certenroll/servername.domain.local_servername-sca.crt

deltacrl location #2  http://wwwca/certenroll/servername-sca.crl

cdp location #2  http://wwwca/certenroll/servername-sca.crl

rca has following unable download errors showing:

aia location #1  http://wwwca/certenroll/servername-rca.crt

cdp location #1  http://wwwca/certenroll/servername-rca.crl

all other locations in sca register ok, no other locations set in rca.  when try access http locations via ie/ff, error 500 - internal server error.  checked authentication on certenroll folder in iis , disabled except anonymous authentication enabled.

rca has certification authority , certification authority web enrollment installed, sca has certificate authority, certification authority web enrollment, , certificate enrollment policy web service installed.

certificates being issued , servers both have green checks on them, it's enterprise pki node shows redx.  don't know if posing major issue/risk?  i'd rather not let sit obviously.  thoughts on how resolve issue?  i've read of other posts , none apply situation seems. 

any @ appreciated.

let me chime in here.

1) not use ldap urls, not best practice. cannot download non-windows , non-domain-joined systems. replication issues (see http://technet.microsoft.com/en-us/library/ee619730(ws.10).aspx a whitepaper co-wrote)

2) looking @ urls previous post:

sca crl:
c:\windows\system32\certsrv\certenroll\<caname><crlnamesuffix>....  ok keep.

ldap:///cn=<catruncatedname><......   eliminate. bad practice
http://wwwca/certenroll/servername-sca.crl   replace wwwca dns cname posts either web server or web cluster. not use netbios names. 

sca aia:
ldap:///cn=<catruncatedname><....  eliminate. bad practice
http://wwwca/certenroll/servername-sca.domain.local_servername-sca.crt  replace wwwca dns cname posts either web server or web cluster. not use netbios names. 
c:\windows\system32\certsrv\certenroll\<serverdnsname>_<....ok keep. should value of 1 if @ registry values.

rca crl:
c:\windows\system32\certsrv\certenroll\<caname>....ok keep.
http://wwwca/certenroll/servername-rca.crl  replace wwwca dns cname posts either web server or web cluster. not use netbios names. 


rca aia:
c:\windows\system32\certsrv\certenroll\<serverdnsname>_<....ok keep.
http://wwwca/certenroll/servername-rca.crt   replace wwwca dns cname posts either web server or web cluster. not use netbios names. 


as unable download. may using proxy. when pkiview.msc console performs download, in security context of computer account. must sure *all* computers/users can reach web server without having provide credential information (anonymous access). also, delta crls, referenced steven, need enable double escaping on web server.

brian



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file