Question(s) while reading Komar's 2008 PKI book


i trying hard understand crl publication points.  these questions part of "windows server 2008 pki , certificate security" book starting on page 114 under topic "defining publication points".

what think has confused me not defining "publication" points on extensions tab, defining "distribution" points.

so seems indicate should defining "pairs" of entries.  1 defines publication point, , entry defining distribution point.  assumption correct?

from example certutil command on page 116:

certutil -setreg ca\crlpublicationurls

"1:%windir%\system32\certsrv\certenroll\%%3%%8%%9.crl\n2:http://www.fabrikam.com/certdata/%%3%%8%%9.crl\n10:ldap:///cn=%%7%%8,cn=%%2,cn=cdp,cn=public key services,cn=services,%%6%%10"

the first part referncing path file put when publish crl.

the second part (the http url) included in certificates issued , goes lookup validity of cert.

the 3rd part what's throwing me.  first explanation on page 117 state "the value 2 disgnates crl's publication point in ad ds".  in table on page 115, value of 2 indicates include url in issued certificates. 

shouldn't 1, value indicates location crl should published?

the example further states "the value 8 include cdp url in ca-issued certificates".

shouldn't 2?

can confirm example single entry doing both defining publishing point , distribution point?

how crl published it, distribute it?  understand in case of offline rootca, must manually transfer it, if rootca joined ad, publishing ad automatically make available on ocsp? when publish crl issuing ca, automatically available on ocsp?

when set ocsp role, make crl's available?

thanks this.

in extentions tab, need define cdp , aia, mean publication points?


Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file