IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationIIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old July 24th, 2005, 07:55 PM
Centrist Centrist is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2005
Posts: 3 Centrist User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 18 m 50 sec
Reputation Power: 0
Unhappy 403.13 errors

I am working with IIS 6.0 on a Windows 2003 server. Right now I'm trying to set up SSL. On the server, I'm using the self-signed cert, and on the client, I'm using a cert issued by my company. And I'm trying to set up an SSL connection between them with these certs.

IIS is set up to require SSL, and I have a CTL with my company's root cert in it. I am fairly sure that the CDP servers are working correctly (and certutil -verify seems to confirm this), but whenever I try to connect from the client, the server quickly returns a 403.13 error. Just in case I'm not using certutil correctly, I used an ldap browser, went to the site, and opened the crl to confirm that my cert was not revoked.

I've been playing around with the metabase settings, and I currentl y have CertCheckMode set to 0. I also upped the RevocationURLRetrievalTimeout because the CRL is a little over 4 MBs.

So my question is, if my cert is valid and certutil can confirm this, why does IIS keep telling me that it can't check the CRL? Is there something else I can check for?

Thanks in advance.

Reply With Quote
  #2  
Old July 25th, 2005, 10:13 AM
Centrist Centrist is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2005
Posts: 3 Centrist User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 18 m 50 sec
Reputation Power: 0
I think I've figured out why I'm having these problems. There are different definitions for the RevocationFreshnessTime and RevocationURLRetrievalTimeout in IIS help, MS Techcenter, and MSDN.

I can't seem to get CertCheckMode="4" to work no matter what definition of the other variables I go by. But if I take everything out of the metabase, it will work.

Can someone definitively explain what the Revocation variables do? Or perhaps give me a better solution to the problem of working with a 4.1 MB CRL?

Reply With Quote
  #3  
Old July 26th, 2005, 02:48 AM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 12th Plane (10500 - 10999 posts)
 
Join Date: Jun 2003
Posts: 10,982 Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 18 h 42 m 27 sec
Reputation Power: 814
Sorry, I'm no help at all when it comes to certs, perhaps someone else can jump in.
__________________
======
Doug G
======
I didn't attend the funeral, but I sent a nice letter saying I approved
of it. --Mark Twain

Reply With Quote
  #4  
Old July 27th, 2005, 03:20 PM
Centrist Centrist is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2005
Posts: 3 Centrist User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 18 m 50 sec
Reputation Power: 0
Anyone?

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationIIS > 403.13 errors


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway
Stay green...Green IT