Certificate on-hold and Delta CRL


hi all

a tricky one: delta crl supports unrevoked certificates? i'm doing next steps:

1) issue client authentication certificate

2) if try use certificate in iis (mapping client certificate) certificate works

3) revoke certificate "certificate on hold" reason

4) publish delta crl. checked certificate appears revoked "certificate on hold" reason

5) if try use certificate in iis (mapping client certificate) certificate doesn't work: iis query delta crl , gives me "certificate revoked" error

6) unrevoke certificate

7) publish delta crl. checked certificate appears revoked "remove crl (8)" reason

8) if try use certificate in iis (mapping client certificate) certificate doesn't work: iis query delta crl , gives me "certificate revoked" error

 

i assume because certificate appears in delta crl, regardless "unrevoked" status, certificate revoked iis server. please, can confirm me normal behaviour? can delta crls support scenario?

thanks in advance , regards

on wed, 22 dec 2010 21:41:29 +0000, victormsa wrote:

i assume because certificate appears in delta crl, regardless "unrevoked" status, certificate revoked iis server. please, can confirm me normal behaviour? can delta crls support scenario?

the problem more first delta crl iis server
retrieved still time valid , therefore iis server did not download
new delta crl published.


paul adare
mvp - identity lifecycle manager
http://www.identit.ca
http://lochanlane.wordpress.com/2010/12/22/so-you-want-custom-ring-tones-on-your-windows-phone-7-device/
modem:  contraction.  in "give me modem cookies."



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file