En fait, je voulais mettre mes CDP sur des URL de type "file://" et il semble que c'est de là que ça vient.
En effet, maintenant j'utilise des URL de type "http://" (j'ai pris la peine d'installer IIS sur un serveur) et apparemment tout est bon.
A part un certain Brian Komar sur le site social.microsoft... et un site qui affirme que les URLs FILE ne sont pas supportés, je n'ai rien vu dans les différents documents.
Citation :
The only ones failing are HTTP URLs, and since it is base CRLs as well as delta CRLs, it probably is not the double-escaping issue (as you guessed).
1) Try each URL from Internet Explorer on different clients (not just the CA)
2) Are you using a proxy server? The machine must be set up to use the proxy server to access the HTTP URLs
3) The root CA is using a NetBIOS name for the HTTP and FILE Urls. Are you manually publishing the root CA certificate and CRL to an online Web server? This should be referenced by a DNS name, not a NetBIOS name
4) The FILE URLs in the root CA are not supported, and should be removed
Brian
|
http://social.technet.microsoft.co [...] 308dd9ce2/
Citation :
To publish the offline Root CA cert and CRL to AD, set the "Include in all CRLs" flag in the Root CA extension properties and use the certutil -dspublish command. Do note that file share CDP (FILE://) is not supported - only LDAP:// and HTTP://. I have tried and it's not going to work. Similarly, you would need to specify where clients and servers can obtain the root cert (i.e. LDAP and/or HTTP) in the "Authority Information Access (AIA)" drop-down setting.
|
http://networkerslog.blogspot.com/ [...] -crls.html
Message édité par houckaye le 22-04-2012 à 19:04:29