Impact of disabling "check for publisher's certificate revocation" option of IE in existing PKI environment
Hi, I have 2Tier PKI infrastructure using 2008 R2 server in my existing environment. we are using certificate for Wireless (WLAN1964) authentication using radius server (NPS). Now we need to install some identity tool for this we have to disable "check for publisher's certificate revocation" in internet explorer in all machines using group policy. I want to know what would be the impact of disabling this option for existing PKI Infrastructure ? Any Suggestion. Thanks in Advance.
September 2nd, 2011 3:24am

The impact is that you may be redirected to a specially crafted web page that installs signed application that is signed by revoked (untrusted) certificate.My weblog: http://en-us.sysadmins.lv PowerShell PKI Module: http://pspki.codeplex.com Windows PKI reference: on TechNet wiki
Free Windows Admin Tool Kit Click here and download it now
September 2nd, 2011 3:52am

What if I set the timeout for CRL to 1 Second inside "Network Retrieval" of "Certificate Path Validation Setting" group policy for entire domain. Does it impact in validating my internal CRL also which is published by my Internal CA's.
September 2nd, 2011 4:08am

yes. This affects to all CRL retrievals.My weblog: http://en-us.sysadmins.lv PowerShell PKI Module: http://pspki.codeplex.com Windows PKI reference: on TechNet wiki
Free Windows Admin Tool Kit Click here and download it now
September 2nd, 2011 4:51am

So last clarification Vadims. What you suggest in this situation, Should I go for disabling IE option "check for publisher's certificate revocation" only or should I configure GPO timeout for CRL to 1 Sec in "Certificate Path Validation Setting". What would be the best solution out of these two. Thanks in Advance
September 2nd, 2011 5:01am

second option is not recommended.My weblog: http://en-us.sysadmins.lv PowerShell PKI Module: http://pspki.codeplex.com Windows PKI reference: on TechNet wiki
Free Windows Admin Tool Kit Click here and download it now
September 2nd, 2011 7:23am

On Fri, 2 Sep 2011 07:15:17 +0000, Ajit_bangalore wrote: Now we need to install some identity tool for this we have to disable "check for publisher's certificate revocation" in internet explorer in all machines using group policy. What software requires you to set this policy? Frankly, if that is indeed a requirement then I'd tell the vendor that you're not going to use their software as it introduces a huge security hole in your network. Paul Adare MVP - Identity Lifecycle Manager http://www.identit.ca People who deal with bits should expect to get bitten. -- Jon Bentley
September 2nd, 2011 8:46am

That's what we are also trying to avoid. Anyway thanks for your suggestion.
Free Windows Admin Tool Kit Click here and download it now
September 2nd, 2011 9:16am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics