Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Adding keys to EFS files - "The revocation function unable to check revocation"

$
0
0

I am having an issue on some, not all, computers while attempting to add user keys to encrypted files using the GUI tools (File Properties-->Advanced-->Details). Encrypting the file itself works fine. When I attempt to add users to an encrypted file, I am getting the error:

"The revocation function was unable to check revocation because the revocation server was offline."

However, I am not having any issues from those same computers when I add users to the encryption using the command line tool cipher.exe (/ADDUSER /USER options).

The issue is not occurring with a particular Windows version. The working and non-working users/computers are on the same network, with no restrictions to the revocation locations (LDAP and HTTP). From one of the non-functioning computers, I verified that I can access the CRL using the HTTP CDP. I do not know a way to test/verify access to the LDAP CDP. I understand that the action of adding users to an encrypted document performs a CRL check. I am at a lost as to why it is failing when I attempt to do this through the GUI from only certain computers. This has just started to happen. Any ideas are appreciate. If anyone even knows exactly how the encryption process checks CRL or if there is a log I can look at, that would be of great help.


Viewing all articles
Browse latest Browse all 12072

Trending Articles