Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Need an online- rather than LDAP-based CRL when issuing user certificates from AD CS Web enrollment

$
0
0

Hello,

The Active Directory Certificate Services feature is working great for us--just one problem.  When user obtains a certificate from Web Enrollment, the CRL is LDAP-based:         

[1]CRL Distribution Point
     Distribution Point Name:
          Full Name:
               URL=ldap:///CN=    ...

The machines running IIS that will be examining these certificates for authentication purposes will not have access to LDAP, hence our question: Is there any way to get Web Enrollment to issue certificates with online- (HTTP-) based revocation lists instead of LDAP-based ones?

Thanks,
BGU


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>