CA ignores ServerPublish flag for .crt files (CACertPublicationURLs)


hello,

i have problem setting certification authority windows server 2008 r2.

i want ca certificate, default published %windir%\system32\certsrv\certenroll, published location in file system (let's say c:\aia).

if try to add location aia extensions using ca gui can't find switch enable publishing (there such swith @ cdp extensions). looking @ registry according topic http://social.technet.microsoft.com/forums/en-us/winserversecurity/thread/d9ae09dd-9815-412d-a9f9-b7c03f6836fe i have set 1 modifier (serverpublish flag) for location publish certificate there (the default location has such modifier -> 1:%windir%\system32\certsrv\certenroll\%1_%3%4.crt). serverpublish flag aia extensions mentioned in micrososft press book windows server 2008 - pki , certificate security brian komar.

if add modifier location (let's 1:c:\aia\%1_%3%4.crt) using regedit or certutil -setreg ca\cacertpublicationurls command , restart ca service entry ignored! certificate published default system32 location if delete aia entries.

i even monitored startup process of certsvc using procmon (sysinternals) , see cacertpublicationurls registry key read. certificate written default location.

either bug or isn't intended copy certificate anoth location (because there no swith on gui). can't find similar problems on internet researches. maybe 1 wants customize name of ca certificate file and copy it automatically other location.

i hope has solution this.

thanks in advance , sorry bad english!

gabor

ca certificate publishing non-default location no longer supported. have manually copy crt file desired destination. since ca certs changed rarely, not problem.
http://en-us.sysadmins.lv


Windows Server  >  Security



Comments

Popular posts from this blog

Motherboard replacement

Remote Desktop App - Error 0x207 or 0x607

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state