Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Change CRL location for internal clients

Reply
Thread Tools Display Modes

Change CRL location for internal clients

 
 
Ondrej Sevecek
Guest
Posts: n/a

 
      05-26-2009
hello,

when a client computer wants to perform CRL check against a public CA's CRL,
it must connect to the CA's HTTP CRL location over a company firewall. The
firewall actually blocks the ougoing requests to the internet where the CRL
location lies.

Is it possible to somehow make the clients (XP, Vista, 2008) download the
CRLs from some internal URL which would be different from the one found in
certificate's CDP location?

thank you very much.

ondrej.


 
Reply With Quote
 
 
 
 
Martin Rublik
Guest
Posts: n/a

 
      05-26-2009
Ondrej Sevecek napisal:
> hello,
>
> when a client computer wants to perform CRL check against a public CA's
> CRL, it must connect to the CA's HTTP CRL location over a company
> firewall. The firewall actually blocks the ougoing requests to the
> internet where the CRL location lies.
>
> Is it possible to somehow make the clients (XP, Vista, 2008) download
> the CRLs from some internal URL which would be different from the one
> found in certificate's CDP location?
>
> thank you very much.
>
> ondrej.
>
>


AFAIK you can't change CRL distribution point, but a workaround is possible. You
can setup DNS record in your internal DNS server and make that record point to
your internal location.

Feel free to ask more questions if needed.

HTH

Martin

--
Replace nospam with google's mail for e-mail communication
 
Reply With Quote
 
Ondrej Sevecek
Guest
Posts: n/a

 
      05-26-2009
thank you very much. this has already occured to me, but I just wanted a
confirmation that there is no other way how to achieve it.

o.



"Martin Rublik" <> wrote in message
news:...
> Ondrej Sevecek napisal:
>> hello,
>>
>> when a client computer wants to perform CRL check against a public CA's
>> CRL, it must connect to the CA's HTTP CRL location over a company
>> firewall. The firewall actually blocks the ougoing requests to the
>> internet where the CRL location lies.
>>
>> Is it possible to somehow make the clients (XP, Vista, 2008) download
>> the CRLs from some internal URL which would be different from the one
>> found in certificate's CDP location?
>>
>> thank you very much.
>>
>> ondrej.
>>
>>

>
> AFAIK you can't change CRL distribution point, but a workaround is
> possible. You
> can setup DNS record in your internal DNS server and make that record
> point to
> your internal location.
>
> Feel free to ask more questions if needed.
>
> HTH
>
> Martin
>
> --
> Replace nospam with google's mail for e-mail communication


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
External VPN clients can't ping / access internal clients James Windows Small Business Server 5 02-19-2008 08:56 AM
Change the default location of temporary download location philipj Internet Explorer 4 04-14-2007 06:48 PM
Change Cache Location in SMS 2003 Clients Pedram Rajabzadeh Scripting 0 09-19-2005 10:21 AM
Internal clients able to FTP out davidcbrown Windows Small Business Server 2 05-21-2005 11:39 PM
VPN Clients and Internal DNS Todd B DNS Server 1 03-23-2005 03:19 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59