Solved

PKI Error Message

Posted on 2014-09-25
4
557 Views
Last Modified: 2014-10-06
I have created a Root CA and a subordinate.  When I import the certificate from root CA to the subordinate I get the followin
error message :

Cannot verify certificate chain. Do you wish to ignore the error and continue ? The revocation function was unable to check revocation because revocation server was offline.

After click on OK and try to start the CA service the following error appear :

The revocation function was unable to check revocation because the revocation server was offlilne.

Has anyone a resolution for the issue ?
0
Comment
Question by:CaussyR
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 81

Expert Comment

by:David Johnson, CD, MVP
ID: 40345366
Tear down and rebuild time.  When you setup the root CA you didn't specify the location that is available for the certificate revocation and probably the AIA records as well. You need to point these to a webserver that already exists on your network.
0
 

Author Comment

by:CaussyR
ID: 40345493
Hi David, appreciate your help.

I do have the followingin the post script :

::Apply the required AIA Extension URLs
certutil -setreg CA\CACertPublicationURLs "1:%windir%\system32\CertSrv\CertEnroll\%%1_%%3%%4.crt\n2:ldap:///CN=%%7,CN=AIA,CN=Public Key Services,CN=Services,%%6%%11\n2:http://CertCentral.stbc3.jstest3.net/CertData/%%1_%%3%%4.crt"

Therefore, do I need this entry to be run ? Can I add the AIA extenstion later ?  Also, does the URL http://CertCentral.stbc3.jstest3.net have to just be available in DNS or does the installation require access to an online site ?  If the installation requires access to an online site, do I need to install the Web Authority option first ?
0
 
LVL 81

Accepted Solution

by:
David Johnson, CD, MVP earned 500 total points
ID: 40348250
A web authority and a CRL are two distinct web pages.
Brian Komar - How not to Screw up your PKI
0
 

Author Closing Comment

by:CaussyR
ID: 40363339
Thanks David for all your assistance and links.
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Ready to improve network connectivity? Watch this webinar to learn how SD-WANs and a one-click instant connect tool can boost provisions, deployment, and management of your cloud connection.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

An article on effective troubleshooting
Windows 10 Creator Update has just been released and I have it working very well on my laptop. Read below for issues, fixes and ideas.
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

729 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question