Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Morning,

I have a query about the certificate required for hybrid key chain deployment, specifically referencing of the CRL.

I have a test deployment of Windows Hello setup and am reviewing the requirements and the documentation states

  • The certificate must have a Certificate Revocation List (CRL) distribution point extension that points to a valid CRL, or an Authority Information Access (AIA) extension that points to an Online Certificate Status Protocol (OCSP) responder.

The MS docs are disjointed so I looked at this

and they are adding a http://crl.domainname on the DC. We have a virtual directory certenroll pointing to the c:\windows\system32\certenroll

Does the cert include the CRL? As the one in the video has a http://crl.domainname added on the CA template for the kerberos certificate.

 

The [1]CRL Distribution Point values on the cert are:

Distribution Point Name: Full Name: URL=ldap:///CN=,CN=,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=,DC=?certificateRevocationList?base?objectClass=cRLDistributionPoint (ldap:///CN=,CN=,CN=CDP,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=,DC=?certificateRevocationList?base?objectClass=cRLDistributionPoint)

 

Confused! I don't want staff to get locked out!

Many Thanks

Darren

Posted

Thank you

Found (or forgot) about certutil, the link is useful

 

As the devices will go away from site but the cert is on the domain controller I am trying to figure out how to get this linked and when and if there is a problem

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...