Quantcast
Viewing all articles
Browse latest Browse all 12072

Unable to Download CDP CRL, DeltaCRL and AIA Location by HTTP

Hi

Just migrated the CA onto Windows Server 2008 R2, which is a DC holding no FSMO roles in a 2003 domain/forest.

I get this in PKIVIEW. (can't post links or images)

AIA Location #2

Unable to download

http://caserver.domain.local/certenroll/caserver.domain.local_domain.crt

DeltaCRL Location #2

Unable to download

http://caserver.domain.local/certenroll/domain+.crl

CDP Location #2

Unable to download

http://caserver.domain.local/certenroll/domain.crl

If I copy and paste the HTTP URL from PKIVIEW, I get

<fieldset>

HTTP Error 500.19 - Internal Server Error

The requested page cannot be accessed because the related configuration data for the page is invalid.

</fieldset>
<fieldset><legend>Detailed Error Information</legend>
ModuleAnonymousAuthenticationModule
NotificationAuthenticateRequest
HandlerStaticFile
Error Code0x8007000d
Config ErrorFailed to decrypt attribute 'password' because the keyset does not exist
Config File\\?\C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config
Requested URLhttp://caserver.domain.local:80/CertEnroll/Impello.crl
Physical PathC:\Windows\system32\CertSrv\CertEnroll\Impello.crl
Logon MethodNot yet determined
Logon UserNot yet determined
</fieldset>
<fieldset><legend>Config Source</legend>
  340:   341:                 <anonymousAuthentication enabled="true" userName="IUSR_CASERVER" password="[enc:AesProvider:AKIysICQmyYDzE7MMPeurKuIWeg6dv13xwaG7af+cq7DNEPpLsQvWXtvMY+uzvMc:enc]" />
  342: 
</fieldset>

(names have been changed to protect the innocent)

I'm guessing the inability to download the CRL/CRT files is related to permissions on the private keys/within the C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys folder. Would re-mapping to the IUSR accounts help as per http://support.microsoft.com/kb/946139/en-gb?

Any thoughts?


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>