Troubleshooting certificates with a focus on Windows 2008 R2 Direct Access

Sometimes application troubleshooting when it comes to digital certificates can lead you to doing an awful lot of reading. In a nutshell there are four things you need to have clear in your mind.

  1. Does the certificate need to be trusted outside of your organisation?
  2. Does the certificate have a revocation list that needs to be checked outside of your organisation?
  3. Is the certificate common name used as a URL?
  4. Does that URL need to be resolved outside of your network?

Let me explain:

  1. Ok hands up ‘Outside of your organisation’ means different things to different people. In a nutshell are the certificates parent(s) in the computers trusted root store? If you have a certificate from the likes of VeriSign its parents will be in virtually every computers trusted root store globally. If the parents are an internal certificate authority then assuming it is an Enterprise CA (Microsoft) then the certificate trust will be distributed to all machines in the Active Directory. If you have multiple Active Directories you have work to do to distribute the certificates via group policy in each one. Microsoft Windows 2008 R2 Direct Access assumes that the client is ‘within your organisation’ so an internal certificate authority is fine as long as the Active Directory the client machine is a member of trusts the Certificate Authority and that the client machine has enrolled for a certificate.
  2. Typically applications check the revocation list, the URL is stamped in the certificate and is typically an HTTP address (internally LDAP is used). By default an internal Microsoft certificate server will NOT publish an externally accessible CRL path. In the case of Direct Access the CRL list is checked and an external path is most certainly needed. This requires a change the certificate server and you need to reissue any certificates so they have the new stamp. While you’re doing that you should also add an external AIA path (this allows expired parent certificates to be replaced when they are renewed).
  3. Some applications check that the name matches the site you are accessing, this is a common mechanism to validate you have not be led down the garden path and think you are accessing your bank and in fact it is a fake site. Other applications actually use the common name of the certificate to determine the target. Direct Access does this to access the direct access server so it’s very important when requesting the certificate to think about the name to use.
  4. By ‘outside of your network’ I mean will the client be resolving names using the internal DNS (Inside your network) or the external DNS (outside of your network). So again highlighting Direct Access the client is most certainly outside of the network and has a certificate (point 2) with a common name that tells it where to go. So the common name must be able to be resolved externally.
  • Share/Bookmark

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

  • ct myelogram pacs system
  • wall bikes brooks saddles
  • breakfast seving tray
  • polish nail dryers
  • fleece henley pullover tops
  • use deepofix to filter mail
  • pattern split riding skirt
  • bearish etf mutual funds
  • hotel nassau inn wildwood
  • kenda executioner mud tires
  • logitech mice keyboard combo mx700
  • recipes for lamb ribs
  • purple floating candles
  • soccer referee delayed foul
  • home made leaf shredder
  • couples transformation retreat
  • victorian boot button bracelet
  • truck grills billet
  • emerald estate jewelry
  • free 3d moving screensavers
  • custom suits in washington dc
  • business briefcase river valley business report
  • troubleshooting eureka vacuum cleaners
  • ornamental iron fence designs
  • find a site for used mopeds
  • rent craps table austin
  • headstones pet memorial
  • cooking with viking pans
  • funky hip scarfs
  • ballet flats size 12
  • hugger mugger yoga products charcoal pilates
  • ingram marine towing
  • allsop metal art corner monitor stand
  • smoked sausage bean
  • ideas for christmas centerpieces
  • cat alarm clock animated video
  • getting skunk odor out of dog
  • 14 k bezel cz earrings
  • stained glass blocks for xmas
  • himalayan cats and kittens for sale
  • shock doctor braces mouth gaurd
  • 2004 simplicity cribs
  • aw table pads
  • fire prevention training material
  • holiday dresses under $70 cyber shop
  • chrome weld racing wheels
  • cheap massage couches
  • towle silver flutes replacement prices
  • mud lite xtr tire
  • autocad 2007 patches for windows vista
  • toyota camry bumper cover
  • heywood wakefield magazine tail table
  • change planes time miles flight airlines
  • resort quest kiawah island condo rental
  • 1983 31 airstream rv layout diagram
  • gameboy advance backyard hockey
  • plastic cutlery trays
  • four stroke evinrude outboard motors
  • fingernail fungal infection
  • retrospect backup
  • pooh fan pulls
  • unpopped popcorn christian company
  • mini van car covers
  • hydrogen cell powered cars
  • toastmaster parts
  • enviro corn stoves in pa
  • vintage toy airplanes funny flyers
  • bluefish fitness wear
  • boutique hotels in bangkok
  • celtic jewelry kelly va
  • tow bar mounted bike racks
  • leveraged inverse financial etf
  • custom nylon horse halters
  • how to clean popcorn maker
  • bath tubs corner jetted
  • tank scooter trunk
  • ideas for christmas stocking stuffers
  • satin pajamas petite
  • vera want napkin rings
  • outdoors umbrellas
  • mulia glass blocks
  • electric hand mixers
  • airsoft colt revolver
  • hotel churchill
  • motorcycle financing guide com
  • buy candy paint online
  • make your own chocolate covered apples
  • timeshares rentals for holidays
  • error code 2753
  • clear shield honda
  • rockport shoes ny listing
  • rack mount nrv10
  • diet after colon removal
  • ladies ballet slippers
  • hot gift recipe chocolate
  • us mortgage payoff calculator
  • electronic waste recycling
  • texas college fund 529
  • ceramic knives for sale
  • sedona arizonal hotels
  • ford money market account logon
  • gorham winfield stainless flatware
  • pet headstones in uk
  • rice chips
  • safe sea trouble
  • miss by elaine sissy
  • arizona fruta vida
  • designer melamine plates
  • education finance online shopping forex market
  • space based browser mmorpg
  • out door gym sets for kids
  • rims and wheels packages
  • comfortable shoes agent
  • 1000 detox foot patch
  • long straight blue 5-6 wig
  • unsecured motorcycle financing
  • new jersey automobile tires buy
  • hot plate cleaning methods
  • frozen margarita maker auction
  • rock bbq pits
  • professional eyelash glue
  • miken hal lite bats
  • microsoft wireless optical keyboard mouse desktop
  • scoreboard decor sports bedroom
  • composite super yachts
  • canadian advice for stock holders
  • discount schrade knives
  • electric stand mixers