Answer the question
In order to leave comments, you need to log in
Certification authority, how to prevent AD users from logging in with revoked certificates?
Good afternoon!
We deployed a certification center in the 2008 domain in order to transfer employees to smart card login. At the same time, we deployed an OCSP responder. During testing, it turned out that users are allowed into the domain even with revoked certificates. Review lists are published every hour, tried to publish manually. The revocation points are written in the certificate. Openssl returns a revoked status when checking an OCSP response.
Tell me where to dig?
Answer the question
In order to leave comments, you need to log in
The client is issued a certificate recorded on a smart card. He calmly authorizes. After we revoke the certificate in the certification authority. We publish a new review list.
Check if the certificate is in the revocation list.
The CA tells us that "This certificate has been revoked by the certification authority that issued it."
But the user quite calmly continues to log in using the revoked certificate.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question