Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Using a CRL

1 view
Skip to first unread message

Martin Sherred

unread,
Apr 9, 2003, 4:55:07 AM4/9/03
to
I have downloaded the CRL from a private CA, saved the
file to disk and then installed the CRL. I selected the
option to have the process automatically select the store
for the CRL.

I can view the CRL, it contains data concerning a revoked
certificate for an internal website. From what I have
pieced together this should be sufficient to prevent this
particular client from making a secure (https) connection
to the web server whose revoked certificate is indicated
in the CRL. But, I am still able to establish an SSL
connection to the web server??? Not sure where I have
gone wrong here. Any suggestions would be appreciated.

David Cross [MS]

unread,
Apr 9, 2003, 8:22:29 AM4/9/03
to
There could be several factors coming into play here:

1. Did you turn revocation on in IE?

2. Are you sure the CRL is installed locally?

3. Are you sure the web server cert is revoked and on the CRL?

4. Are you sure there is no CRL previously issued and cached?

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/prodtechn
ol/WinXPPro/support/tshtcrl.asp

--


David B. Cross [MS]

--
This posting is provided "AS IS" with no warranties, and confers no rights.

http://support.microsoft.com

"Martin Sherred" <mshe...@comcast.net> wrote in message
news:019801c2fe75$b82ed1a0$3401...@phx.gbl...

Martin Sherred

unread,
Apr 9, 2003, 1:43:16 PM4/9/03
to
>.Thanks for your comments. In fact "Check for server
certificate revocation" in IE had not been enabled. Odd
that it is not enabled by default.
>

David Cross [MS]

unread,
Apr 10, 2003, 8:31:41 AM4/10/03
to
It is enabled by default in Windows Server 2003 and all future versions of
the operating system

--


David B. Cross [MS]

--
This posting is provided "AS IS" with no warranties, and confers no rights.

http://support.microsoft.com

"Martin Sherred" <mshe...@comcast.net> wrote in message

news:04bb01c2febf$80834390$3401...@phx.gbl...

0 new messages