<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx</link><description>[Today's post is provided by Carol Bailey ] 
 By default, an issuing enterprise CA publishes its certificate revocation list (CRL) to locations within the forest. When you are using Internet-based client management with Configuration Manager, there are</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx#3478656</link><pubDate>Fri, 03 Feb 2012 00:44:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3478656</guid><dc:creator>Jrod</dc:creator><description>&lt;p&gt;What is the web server is in a separate forest? &amp;nbsp;Anything special I need to do? &amp;nbsp;I am getting an error: &amp;nbsp;AD CS Error: &amp;quot;The directory name is invalid.&amp;quot; 0x8007010b (WIN32/HTTP:267)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3478656" width="1" height="1"&gt;</description></item><item><title>re: How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx#3454137</link><pubDate>Mon, 19 Sep 2011 11:43:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3454137</guid><dc:creator>VaKim</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Is there a way to automatically copy the CRL file to the web server through HTTP, instead of file share?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3454137" width="1" height="1"&gt;</description></item><item><title>re: How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx#3453816</link><pubDate>Fri, 16 Sep 2011 19:53:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3453816</guid><dc:creator>VaKim</dc:creator><description>&lt;p&gt;I am wondering if we can automatically publish the CRL through http instead of file share?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3453816" width="1" height="1"&gt;</description></item><item><title>re: How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx#3299680</link><pubDate>Thu, 10 Dec 2009 18:13:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3299680</guid><dc:creator>Vadims Podans</dc:creator><description>&lt;P&gt;&amp;gt; Does it also need to be accessible over the internet for clients that cannot access the AIA publication location within the intranet?&lt;/P&gt;
&lt;P&gt;yes. However I don't think that this is necessary to change AIA extension, because usually CA has certificates with 5 or more year of validity. So you may manually copy CA certs to remote server.&lt;/P&gt;
&lt;P&gt;also I have another comment for this post. Consider to implement OCSP responder on WebServer. This will decrease a load to Web Server (in cases if your CRL size is more than 10-20kb.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3299680" width="1" height="1"&gt;</description></item><item><title>re: How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx#3299679</link><pubDate>Thu, 10 Dec 2009 18:05:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3299679</guid><dc:creator>Vadims Podans</dc:creator><description>&lt;P&gt;Hello tomt!&lt;/P&gt;
&lt;P&gt;&amp;gt; how (where) can I specify the http url for the DELTA crl???&lt;/P&gt;
&lt;P&gt;to CRL file name just add option &amp;lt;DeltaCRLAllowed&amp;gt;. This will add plus sign ('+') to Delta CRL. This option instructs the server to publish 2 (instead of 1) CRL files. Both CRL's will have the same name but DeltaCRL file will contain plus sign.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3299679" width="1" height="1"&gt;</description></item><item><title>re: How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx#3283616</link><pubDate>Mon, 28 Sep 2009 22:28:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3283616</guid><dc:creator>Josh</dc:creator><description>&lt;p&gt;Carol, &amp;nbsp;Excellent post. &amp;nbsp;What about the AIA? &amp;nbsp;Does it also need to be accessible over the internet for clients that cannot access the AIA publication location within the intranet?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Josh&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3283616" width="1" height="1"&gt;</description></item><item><title>re: How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx#3275045</link><pubDate>Wed, 19 Aug 2009 20:41:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3275045</guid><dc:creator>Founda</dc:creator><description>&lt;p&gt;Thats: &lt;/p&gt;
&lt;p&gt;http://&amp;lt;FQDN_of_Web_Server&amp;gt;/&amp;lt;CRL_directory_name&amp;gt;/&amp;lt;CaName&amp;gt;&amp;lt;CRLNameSuffix&amp;gt;&amp;lt;DeltaCRLAllowed&amp;gt;.crl &amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3275045" width="1" height="1"&gt;</description></item><item><title>re: How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx#3272940</link><pubDate>Thu, 13 Aug 2009 04:24:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3272940</guid><dc:creator>Carol Bailey - MSFT</dc:creator><description>&lt;p&gt;Thanks for your feedback Thomas, and I'm sorry it's taken me a while to investigate this. &amp;nbsp;To publish the delta CRL, the instructions were missing the variable &amp;lt;DeltaCRLAllowed&amp;gt; in the paths, and I've now added this and updated the instructions. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;As a rule, I'm not fond of adding variables in documentation when they are not needed for basic functionality, but this one is needed for delta CRLs. &amp;nbsp;I also added &amp;lt;CaName&amp;gt; so that you can publish CRLs from different CAs into the same location (for example, you have a tiered CA hierarchy), and &amp;lt;CRLNameSuffix&amp;gt; according to best practices (&lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/library/dd379469"&gt;http://technet.microsoft.com/en-us/library/dd379469&lt;/a&gt;(WS.10).aspx).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3272940" width="1" height="1"&gt;</description></item><item><title>re: How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx#3254021</link><pubDate>Fri, 12 Jun 2009 16:29:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3254021</guid><dc:creator>thomas torggler</dc:creator><description>&lt;p&gt;hi carol,&lt;/p&gt;
&lt;p&gt;thank you for this great blog!&lt;/p&gt;
&lt;p&gt;but I have one question: how (where) can I specify the http url for the DELTA crl??? I'm able to auto-update the full crl on a web server, but the delta crl is always trying to connect to the standard http url... is there a possibility to change this?&lt;/p&gt;
&lt;p&gt;best reguards&lt;/p&gt;
&lt;p&gt;thomas t.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3254021" width="1" height="1"&gt;</description></item><item><title>How to Publish the CRL on a Separate Web Server</title><link>http://blogs.technet.com/b/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx#3235651</link><pubDate>Tue, 05 May 2009 16:06:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3235651</guid><dc:creator>The Configuration Manager Support Team Blog</dc:creator><description>&lt;p&gt;Just in case you missed it, Carol Bailey has another fantastic post over on this System Center Configuration&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3235651" width="1" height="1"&gt;</description></item></channel></rss>