<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Windows PKI blog : troubleshooting</title><link>http://blogs.technet.com/pki/archive/tags/troubleshooting/default.aspx</link><description>Tags: troubleshooting</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>The EASY way of CRL troubleshooting in Windows Vista</title><link>http://blogs.technet.com/pki/archive/2006/12/16/the-easy-way-of-crl-troubleshooting-in-windows-vista.aspx</link><pubDate>Sat, 16 Dec 2006 20:04:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:559408</guid><dc:creator>MS2065</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/pki/comments/559408.aspx</comments><wfw:commentRss>http://blogs.technet.com/pki/commentrss.aspx?PostID=559408</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-themecolor: accent5; mso-themeshade: 191"&gt;Easy CRL troubleshooting is just one click away i&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-themecolor: accent5; mso-themeshade: 191"&gt;n Windows Vista&lt;/SPAN&gt;! Read on to learn how to enable crypto API2 (CAPI2) logging.&amp;nbsp;For Windows XP and Windows Server 2003 you still have to use &lt;A class="" title=CAPIMON href="http://www.microsoft.com/downloads/details.aspx?familyid=0bfe87a8-4e79-4441-9d4c-0cab35d49a01&amp;amp;displaylang=en" target=_blank mce_href="http://www.microsoft.com/downloads/details.aspx?familyid=0bfe87a8-4e79-4441-9d4c-0cab35d49a01&amp;amp;displaylang=en"&gt;CAPIMON&lt;/A&gt;&amp;nbsp;to find out what's going wrong with CRL checking.&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;DIV class=NumberedList1 style="MARGIN: 3pt 0cm 3pt 18pt; mso-list: l0 level1 lfo3"&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;Log on with local administrator permissions to the computer where the &lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-themecolor: accent5; mso-themeshade: 191"&gt;certificate verification failure &lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;occurs.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=NumberedList1 style="MARGIN: 3pt 0cm 3pt 18pt; mso-list: l0 level1 lfo3"&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;Click the &lt;B style="mso-bidi-font-weight: normal"&gt;Start&lt;/B&gt; menu. On the &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Administrative Tools&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt; menu, click &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Event Viewer&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=NumberedList1 style="MARGIN: 3pt 0cm 3pt 18pt; mso-list: l0 level1 lfo3"&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;In the left pane, expand the &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Application Logs&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt; container, expand &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Microsoft&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="FONT-WEIGHT: normal; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;, expand &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Windows&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="FONT-WEIGHT: normal; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;and then expand the &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;CAPI2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt; container. Select the &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Operational&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt; container.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=NumberedList1 style="MARGIN: 3pt 0cm 3pt 18pt; mso-list: l0 level1 lfo3"&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;On the &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt; menu, click &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Properties&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=NumberedList1 style="MARGIN: 3pt 0cm 3pt 18pt; mso-list: l0 level1 lfo3"&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;In the &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;General&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt; tab, select the &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Enable logging&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="FONT-WEIGHT: normal; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt; check box&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;, adjust the maximum log size and log maintenance according to your needs, and then click &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;With CAPI2 logging turned on, all chain validation operations are logged in the event log: &lt;/SPAN&gt;&lt;SPAN class=Italic&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #31849b; FONT-STYLE: normal; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-size: 9.0pt"&gt;&lt;STRONG&gt;Application logs - Microsoft - Windows - CAPI2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-themecolor: accent5; mso-themeshade: 191"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;To find out what goes wrong with chain validation do the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;DIV class=NumberedList1 style="MARGIN: 3pt 0cm 3pt 18pt; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-fareast-font-family: 'Lucida Sans Unicode'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;Open the event log on the computer where the chain validation fails and make sure CAPI2 logging is enabled.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=NumberedList1 style="MARGIN: 3pt 0cm 3pt 18pt; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;In &lt;B style="mso-bidi-font-weight: normal"&gt;Event Viewer&lt;/B&gt;, expand the following container structure in the left pane: &lt;/SPAN&gt;&lt;SPAN class=Italic&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="COLOR: #31849b; FONT-STYLE: normal; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;Application logs - Microsoft - Windows - CAPI2 - Operational&lt;/SPAN&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=NumberedList1 style="MARGIN: 3pt 0cm 3pt 18pt; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;In the right pane, select a log entry.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=NumberedList1 style="MARGIN: 3pt 0cm 3pt 18pt; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;In the bottom window, click the &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Details&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt; tab, and then select the &lt;/SPAN&gt;&lt;SPAN class=Bold&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;&lt;STRONG&gt;Friendly View&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=NumberedList1 style="MARGIN: 3pt 0cm 3pt 18pt; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;You will clearly see which process has performed a CAPI2 operation and what the actual status code was.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;SPAN style="COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'"&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;Additional information about PKI troubleshooting on Vista is available on Technet. Refer to&amp;nbsp;&lt;A class="" title="Troubleshooting PKI Problems on Windows Vista" href="http://technet2.microsoft.com/WindowsVista/en/library/771e1f29-4eba-40c9-9193-60043889bbf41033.mspx" mce_href="http://technet2.microsoft.com/WindowsVista/en/library/771e1f29-4eba-40c9-9193-60043889bbf41033.mspx"&gt;Troubleshooting PKI Problems on Windows Vista&lt;/A&gt;&amp;nbsp;or download the documentation from the Microsoft &lt;A class="" title="Troubleshooting PKI Problems on Windows Vista" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=fe8eb7ea-68da-4331-9d38-bdbf9fa2c266&amp;amp;DisplayLang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=fe8eb7ea-68da-4331-9d38-bdbf9fa2c266&amp;amp;DisplayLang=en"&gt;Download Center&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #31849b; FONT-FAMILY: 'Lucida Sans Unicode','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;Carsten&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=559408" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/pki/archive/tags/troubleshooting/default.aspx">troubleshooting</category><category domain="http://blogs.technet.com/pki/archive/tags/Vista/default.aspx">Vista</category></item></channel></rss>