VPN revocation error?


i have managed configure sstp vpn connection on internal client pc, through registry fixes. keep getting error relating checking see if server has been revoked.......

"the revocation function unable check revocation because revocation server offline."

i've gone onto revoked certificates in ca , clicked on publish , created new crl clients not getting or not working somehow. idea how can fix this?

update: have noticed on the certificates i’m using ldap being used method of retrieving crl. dont mind anyway because i'm not interested in http @ moment, dont know why domain joined users , computers cannot find cdp through ldap?


ldap:///cn=jedi-ca,cn=jedi,cn=cdp,cdp=public key services,cn=services,cn=configuration,dc=starwars,dc=com?certificaterevocationlist?base?objectclass=crldistributionpoint

^^^ ldap directory on certificate 


you have chicken , egg issue (hence why should *never* user ldap urls in cdp/aia).

you want connect sstp vpn, need check revocation status of certificate on vpn server. check status, need connect ad download ldap url in cdp/aia. cannot, because have not connected. need connect download url, cannot download because have not connected... repeat ad nauseum.

cdp , aia urls in vpn scenario must published http location both internally , externally accessible using same dns name... period.

brian



Windows Server  >  Security



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607