Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > AD Certificate Services CRL Visible to Internet

Reply
Thread Tools Display Modes

AD Certificate Services CRL Visible to Internet

 
 
POB
Guest
Posts: n/a

 
      03-19-2010
This problem was brought to my attention while attempting to implement SSTP
VPN connections to a Windows Server 2008 R2 Server (it is also the root CA
and only CA in the forest). Users who attempt to connect receive the
following error: “Error 0x80092013: The revocation function was unable to
check revocation because the revocation server was offline.” In response the
error, I read Microsoft Article Article ID: 961880,and followed the steps
outlined in the article.

I also scanned ADCS for best practices, and it returns the following
warning: “The certificate revocation list (CRL) distribution point extension
on this certification authority (CA) includes URIs for a remote Web server.
If the Web server is Internet Information Services (IIS) 7.0 with the default
configuration, then delta CRL URIs that contain a plus sign (+) will be
blocked.” It says to resolve the problem, ensure that the “allow double
escaping" check box is selected in the IIS Request Filtering settings. I
have confirmed that it is checked.

What I have done so far:
1. Delete the prior http location from the extensions tab of the CA
2. Enter a new http location with the public IP e.g.
http://1.1.1.1/CertEnroll/<CaName><CRLNameSuffix><DeltaCRLAllowed>.crl
3. Checked the Include in CRL box, and the include in the CDP box
4. Revoked the old SSL certificate, and re-issued a new one
5. Re-bound the SSL certificate to 443 in IIS
6. Associated the new certificate in RAS
7. Ensured that “allow double escaping” was checked in IIS for the
certenroll site

How do I resolve this problem?

 
Reply With Quote
 
 
 
 
Paul Bergson [MVP-DS]
Guest
Posts: n/a

 
      03-19-2010
Hopefully your ca is inside your enterprise, you should probably take your
root server offline and bring up an issuing ca as well. We just alias out
the name of our internal server with an external site and make the path the
exact same as the internal crl and it works for us.

This really has nothing to do with AD, so I have cross posted with the
security NewsGroup. You will probably get more details on this from someone
over there.

--
Paul Bergson
MVP - Directory Services
MCITP - Enterprise Administrator
MCTS, MCT, MCSE, MCSA, MCP, Security +, BS CSci
2008, Vista, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewGroups. This
posting is provided "AS IS" with no warranties and confers no rights.
"POB" <> wrote in message
news:02A8902D-0622-4BB4-BB55-...
> This problem was brought to my attention while attempting to implement
> SSTP
> VPN connections to a Windows Server 2008 R2 Server (it is also the root CA
> and only CA in the forest). Users who attempt to connect receive the
> following error: "Error 0x80092013: The revocation function was unable to
> check revocation because the revocation server was offline." In response
> the
> error, I read Microsoft Article Article ID: 961880,and followed the steps
> outlined in the article.
>
> I also scanned ADCS for best practices, and it returns the following
> warning: "The certificate revocation list (CRL) distribution point
> extension
> on this certification authority (CA) includes URIs for a remote Web
> server.
> If the Web server is Internet Information Services (IIS) 7.0 with the
> default
> configuration, then delta CRL URIs that contain a plus sign (+) will be
> blocked." It says to resolve the problem, ensure that the "allow double
> escaping" check box is selected in the IIS Request Filtering settings. I
> have confirmed that it is checked.
>
> What I have done so far:
> 1. Delete the prior http location from the extensions tab of the CA
> 2. Enter a new http location with the public IP e.g.
> http://1.1.1.1/CertEnroll/<CaName><CRLNameSuffix><DeltaCRLAllowed>.crl
> 3. Checked the Include in CRL box, and the include in the CDP box
> 4. Revoked the old SSL certificate, and re-issued a new one
> 5. Re-bound the SSL certificate to 443 in IIS
> 6. Associated the new certificate in RAS
> 7. Ensured that "allow double escaping" was checked in IIS for the
> certenroll site
>
> How do I resolve this problem?
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Internet Explorer cannot display the webpage Laura Internet Explorer 14 04-16-2010 10:46 PM
Security Failures after Password Change Zachary Server Security 14 10-30-2009 06:02 PM
Re: Incorrect server name Ace Fekay [MCT] Windows Server 4 10-28-2009 02:17 PM
Re: Certificate Services and Synching with Exchange Chris De Herrera ActiveSync 0 08-13-2006 07:44 PM
5342 and 5365 are indeed under an NDA. Kevin John Panzke Windows Vista General Discussion 38 05-04-2006 06:32 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59