CA ignores ServerPublish flag for .crt files (CACertPublicationURLs)
hello,
i have problem setting certification authority windows server 2008 r2.
i want ca certificate, default published %windir%\system32\certsrv\certenroll, published location in file system (let's say c:\aia).
if try to add location aia extensions using ca gui can't find switch enable publishing (there such swith @ cdp extensions). looking @ registry according topic http://social.technet.microsoft.com/forums/en-us/winserversecurity/thread/d9ae09dd-9815-412d-a9f9-b7c03f6836fe i have set 1 modifier (serverpublish flag) for location publish certificate there (the default location has such modifier -> 1:%windir%\system32\certsrv\certenroll\%1_%3%4.crt). serverpublish flag aia extensions mentioned in micrososft press book windows server 2008 - pki , certificate security brian komar.
if add modifier location (let's 1:c:\aia\%1_%3%4.crt) using regedit or certutil -setreg ca\cacertpublicationurls command , restart ca service entry ignored! certificate published default system32 location if delete aia entries.
i even monitored startup process of certsvc using procmon (sysinternals) , see cacertpublicationurls registry key read. certificate written default location.
either bug or isn't intended copy certificate anoth location (because there no swith on gui). can't find similar problems on internet researches. maybe 1 wants customize name of ca certificate file and copy it automatically other location.
i hope has solution this.
thanks in advance , sorry bad english!
gabor
http://en-us.sysadmins.lv
Windows Server > Security
Comments
Post a Comment