Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Unable to Download CDP CRL, DeltaCRL and AIA Location by HTTP

$
0
0

Hi

Just migrated the CA onto Windows Server 2008 R2, which is a DC holding no FSMO roles in a 2003 domain/forest.

I get this in PKIVIEW. (can't post links or images)

AIA Location #2

Unable to download

http://caserver.domain.local/certenroll/caserver.domain.local_domain.crt

DeltaCRL Location #2

Unable to download

http://caserver.domain.local/certenroll/domain+.crl

CDP Location #2

Unable to download

http://caserver.domain.local/certenroll/domain.crl

If I copy and paste the HTTP URL from PKIVIEW, I get

<fieldset>

HTTP Error 500.19 - Internal Server Error

The requested page cannot be accessed because the related configuration data for the page is invalid.

</fieldset>
<fieldset><legend>Detailed Error Information</legend>
ModuleAnonymousAuthenticationModule
NotificationAuthenticateRequest
HandlerStaticFile
Error Code0x8007000d
Config ErrorFailed to decrypt attribute 'password' because the keyset does not exist
Config File\\?\C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config
Requested URLhttp://caserver.domain.local:80/CertEnroll/Impello.crl
Physical PathC:\Windows\system32\CertSrv\CertEnroll\Impello.crl
Logon MethodNot yet determined
Logon UserNot yet determined
</fieldset>
<fieldset><legend>Config Source</legend>
  340:   341:                 <anonymousAuthentication enabled="true" userName="IUSR_CASERVER" password="[enc:AesProvider:AKIysICQmyYDzE7MMPeurKuIWeg6dv13xwaG7af+cq7DNEPpLsQvWXtvMY+uzvMc:enc]" />
  342: 
</fieldset>

(names have been changed to protect the innocent)

I'm guessing the inability to download the CRL/CRT files is related to permissions on the private keys/within the C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys folder. Would re-mapping to the IUSR accounts help as per http://support.microsoft.com/kb/946139/en-gb?

Any thoughts?


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>