Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

certutil -crl problems (the directory name is invalid)

$
0
0

Another problem for you fine experts to consider...2 tier PKI, offline Root 2008 R2, 1 Sub Ent CA in Domain1 (2008 R2) and 1 Sub Ent CA in Domain2 (2012 R2).

SubCA 1 and 2 are configured pretty much identically, however when setting up SubCA 2 I am having issues running the Certutil -CRL command to publish the CRL.

My CDP locations are configured as follows;

65:c:\WIndows\System32\CertSrv\CertEnroll\%3%8%9.crl
79:ldap://CN=%7%8,CN=CDP,CN=Public Key Services,CN=Services,%6%10
6:http://pki.domain2/CertEnrolment/%3%8%9.crl
65:file://\\pki.domain2\CertEnrolment\%3%8%9.crl

I can confirm that the base CRL publishes correctly to the CertEnroll location and LDAP correctly. But it fails trying to publish to the HTTP/File location (which is the same path).

I get the error:

CertUtil: -CRL command FAILED: 0x8007010b (WIN32/HTTP: 267 ERROR_DIRECTORY)

CertUtil: The directory name is invalid

Also the Delta CRL fails on the CertEnroll default directory as well as the file/http path with error;

Active Directory Certificate Services could not publish a Delta CRL for key 0 to the following location: file://\\pki.domain\CertEnrolment\CANAME+.crl. Operation aborted 0x80004004 (-2147467260 E_ABORT)<o:p></o:p>

I'm pretty certain it's not a permissions issue as I've added Everyone for NTFS/share permissions to test without any change. The install was done with an Enterprise Admin account but I'm doing all the testing now with a normal admin account (admin in the CA/server but not domain or enterprise admin).<o:p></o:p>

<o:p></o:p>

The File/HTTP location is on the CA itself (I know this is likely not best practise, but needs to be there in the short term) so not sure if the Windows firewall comes into play.

Thanks!



Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>