VPN revocation error?
i have managed configure sstp vpn connection on internal client pc, through registry fixes. keep getting error relating checking see if server has been revoked.......
"the revocation function unable check revocation because revocation server offline."
i've gone onto revoked certificates in ca , clicked on publish , created new crl clients not getting or not working somehow. idea how can fix this?
update: have noticed on the certificates i’m using ldap being used method of retrieving crl. dont mind anyway because i'm not interested in http @ moment, dont know why domain joined users , computers cannot find cdp through ldap?
ldap:///cn=jedi-ca,cn=jedi,cn=cdp,cdp=public key services,cn=services,cn=configuration,dc=starwars,dc=com?certificaterevocationlist?base?objectclass=crldistributionpoint
^^^ ldap directory on certificate
you have chicken , egg issue (hence why should *never* user ldap urls in cdp/aia).
you want connect sstp vpn, need check revocation status of certificate on vpn server. check status, need connect ad download ldap url in cdp/aia. cannot, because have not connected. need connect download url, cannot download because have not connected... repeat ad nauseum.
cdp , aia urls in vpn scenario must published http location both internally , externally accessible using same dns name... period.
brian
Windows Server > Security
Comments
Post a Comment