Can't find CRL, when the CRL location points to LDAP (ldap:///)
i'm trying verify digital signature in adobe. crl of certificate pointed ldap url (ldap:///cn=root,cn=cdp,cn=public key services,cn=services,cn=configuration,dc=test,dc=local?certificaterevocationlist?base?obj ectclass=crldistributionpoint).
the error appears in adobe:
crl download error
location: ldap:///cn=root,cn=cdp,cn=public key services,cn=services,cn=configuration,dc=test,dc=local?certificaterevocationlist?base?obj ectclass=crldistributionpoint
cannot connect server.____________________________________________________________
crl download error
location: ldap:///cn=root,cn=cdp,cn=public key services,cn=services,cn=configuration,dc=test,dc=local?certificaterevocationlist?base?obj ectclass=crldistributionpoint
cannot connect server.____________________________________________________________
crl download error
location: ldap:///cn=root,cn=cdp,cn=public key services,cn=services,cn=configuration,dc=test,dc=local?certificaterevocationlist?base?obj ectclass=crldistributionpoint
cannot connect server.
i should mention when use certificate cdp entry points http url, don't such errors. known bug/limitation? fixed? there way allow/force adobe read ldap url?
p.s.
i'm aware un-checking "require certificate revocation checking succeed whenever possible during signature verification" solves issue (as skips crl checking), prefer have crl check working
same problem, here :-(
More discussions in Security & Digital Signatures
adobe
Comments
Post a Comment