Subordinate Certification authority problem

  • Thread starter Thread starter Filippo
  • Start date Start date
F

Filippo

Hello

I'm tryng to install a certification schema like this:
- Standalone Root Certification Authority (offline, not connected to
network) based on Windows 2003 Server
- Enterprise Subordinate Certification Authority (for certificate management
of Active Directory Users and smart cards as well) based on Windows 2003
Server
- Active Directory (One or more DC based on Windows 2003 Server)
I read the to-do-list of Windows 2003 Support and technet, but encountered
this problem:
the subordinate Certification Authority fails to start (or, downgrading its
check level, to release certificates) because it cannot find the certificate
revocation list (crl) of the root one. But I'm sure the location (specified
as Microsoft document suggests in root ca extensions properties - in this
case a file share) is available to subordinate ca and dc.
During procedure, the proposed command "certutil -dspublish -f namefile.crl"
fails due to a missing parameters, that I identified with the ca name.
Any suggestions?

Thank you
Filippo
 
Publish the Root CA CRL to a location that the subordinate CA can locate.
The Subordinate CA certificate will need to be updated to reflect a new
path. You will need to update the Root CA with the new CRL path in the
x.509 extensions and issue a new subordinate CA certificate from the
request.

--Shawn
This posting is provided "AS IS" with no warranties and confers no rights.
 
Back
Top