Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > General Security

General Security Post any general questions related to security, viruses or spyware here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 12th January 2009   #1
Member
 
Profile:
Join Date: Dec 2007
Location: Maryland
Posts: 25
Computer Experience:
Intermediate
batsona Reputation Level


Question How XP deals with Revocation Lists...

Can someone point me toward a whitepaper, or article that describes how Windows deals with Certerficate Revocation Lists? (CRLs) Or, can someone briefly describe it?

Briefly, here's my scenario: I am running an Enterprise Patch Management system, "PatchLink", by a company called Lumension. The managed clients 'check in' with the server periodically. They do this over HTTPS, which utilizes an SSL certificate. Now, the corresponding CRL for the SSL certificate must be current, or the check-in fails.

My big question, is that when the CRL expires, how is a new copy downloaded? Does the OS itself initiate this, or does the application have a way of doing this? If the application does it, then they're the issue of proxy. The Managed Clients are on a protected network with no direct Internet access, but there is a SOCKS proxy. Anything that routes thru IE, or can be made to use "Window's Proxy Settings" will work, but if [whatever] requests the proxy can't be made to user the browser's proxy settings, then the Managed Client can't get out to the Internet to find an updated CRL.

In this case, an admin has to go to the machine once a week, and manually install a CRL. My last issue, is that when a Managed Client is a Win2K3 system, it checks the CRL, and if its expired, the client doesn't check in anymore. XP machines pretty much check in all the time, but just recently I have a few that stop checking in once the CRL expires. I bet its a setting with the PatchLink client, and not inside Windows, that causes this checking to occur.

Anyway, If I understand more about how Windows deals with CRLs, i'll be better equiped to solve this problem...

Thanks!

batsona is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 12th January 2009   #2
Administrator
Microsoft MVP
 
Arie's Avatar
 
Profile:
Join Date: Dec 2001
Location: Birkirkara, Malta
Posts: 8,805
Computer Experience:
***
Arie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation Level

My System

Here's a white paper from Microsoft's TechNet: Certificate Revocation and Status Checking

Not my expertise, I just know what/where to look

Arie is offline   Reply With Quote
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Old email addresses/distribution lists showing in Outlook 2007] sshear01 Microsoft Mail (Outlook / Outlook Express / Windows Mail) 1 5th October 2008 15:39
Outlook Express - Creating distribution lists... roystacy Microsoft Mail (Outlook / Outlook Express / Windows Mail) 2 13th August 2007 21:15
address book lists Suzette Firefox, Thunderbird & SeaMonkey 4 29th April 2006 17:52
Exporting Outlook Express Distribution Lists Josie Internet Explorer 1 29th August 2005 03:30
Sending Messages to Multiple Address Lists Carolindc Firefox, Thunderbird & SeaMonkey 3 9th July 2003 16:09


All times are GMT +1. The time now is 03:12.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]