User Tools

Site Tools


nps:pki:aiacdp

AIA/CDP

Default values (AIA) (None AD member)

1:C:\Windows\System32\CertSvc\CertEnroll\%1_%3%4.crt
0:ldap:///CN=%7,CN=AIA,CN=Public Key Services,CN=Services,%6%11
0:http://%1/CertEnroll/%1_%3%4.crt
2:file://%1/CertEnroll/%1_%3%4.crt

Default values (CDP (CRL)) (None AD Member)

65:C:\Windows\System32\CertSvc\CertEnroll\%3%8%9.crl
8:ldap:///CN=%7%8,CN=CDP,CN=Public Key Services,CN=Services,%6%10
0:http://%1/CertEnroll/%3%8%9.crl
6:file://%1/CertEnroll/%3%8%9.crl

Default values (AIA) (AD member)

1:C:\Windows\System32\CertSvc\CertEnroll\%1_%3%4.crt
3:ldap:///CN=%7,CN=AIA,CN=Public Key Services,CN=Services,%6%11
0:http://%1/CertEnroll/%1_%3%4.crt
2:file://%1/CertEnroll/%1_%3%4.crt

Default values (CDP (CRL)) (AD Member)

65:C:\Windows\System32\CertSvc\CertEnroll\%3%8%9.crl
79:ldap:///CN=%7%8,CN=CDP,CN=Public Key Services,CN=Services,%6%10
0:http://%1/CertEnroll/%3%8%9.crl
0:file://%1/CertEnroll/%3%8%9.crl

Settings used in AIA/CDP

VariableGUINAMENameExample
%1?ServerDNSName(FQDN)
%2<ServerShortName> ServerShortName (Netbios)HostName
%3<CaName> CA NameCommonName
%4<CertificateName> CertificateName
%5 Domain DNDSDomainDN
%6<ConfigurationContainer> ConfigDNDSConfigDN
%7<CATruncatedName> CATruncatedName CommonName?
%8<CRLNameSuffix> CRLNameSuffix
%9<DeltaCRLAllowed> DeltaCRLAllowed
%10<CDPObjectClass> CDPObjectClass
%11<CAObjectClass> CAObjectClass
?SYSTEMC:\Windows\System32

CRL Flags

BitValueNameExplain
01CSURL_SERVERPUBLISHPublish CRLs to this location. (Write CRL as a file (or LDAP) to this location
12CSURL_ADDTOCERTCDPInclude in the CDP extension of Issued certificates
24CSURL_ADDTOFRESHESTCRLInclude in CRLs.Clients use this to find Delte CRL locations
38CSURL_ADDTOCRLCDPInclude in all CRLs. Spescifies where to publish in the Active Directory when publishing manually.
416CSURL_PUBLISHRETRY
532CSURL_ADDTOCERTOCSP
664CSURL_SERVERPUBLISHDELTAPublish Delta CRLs to this location
7128CSURL_ADDTOIDPInclude in the IDP Extension of CRLs

AIA Flags

BitValueNameExplain
01Config_CA_CACert_Publish_ToThe CA publishes its signing certificate to this location.
12Config_CA_AIA_Include_In_CertInclude in AIA extension of certificates (Write this location into the AIA part of all certificates issued)
532Config_CA_OCSP_IncludeInclude in the online certificate status protocol (OCSP) extension
nps/pki/aiacdp.txt ยท Last modified: 2019/03/18 10:56 by admin