Issuer's V2 Certificate Revocation List has an unknown critical extension

- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Issuer's V2 Certificate Revocation List has an unknown critical extension
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-24-2018 10:20 AM
The following messages appear repeatedly on my servers in /var/log/centrify_mapper_error.log
Doing /var/centrify/net/certs
Doing /var/centrify/net/certs
Doing /var/centrify/net/certs
Doing /var/centrify/net/certs
Doing /var/centrify/net/certs
crlutil: unable to import CRL: SEC_ERROR_CRL_UNKNOWN_CRITICAL_EXTENSION: Issuer's V2 Certificate Revocation List has an unknown critical extension.
Centrify Smart Card support is disabled.
Can these messages be ignored?
RHEL7.5
CentrifyDC-5.3.1-398.x86_64
CentrifyDC-openssh-7.2p2-5.3.1.391.x86_64
Re: Issuer's V2 Certificate Revocation List has an unknown critical extension
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-24-2018 12:54 PM
Welcome to the Centrify forums. Although the question is not directly-related to Centrify (it's more a Public Key Infrastructure question), in general you really want to understand what PKI messages mean and document the message exception with your security teams.
What's happening here?
In Active Directory, most likely you have a PKI auto-enrollment policy that is issuing a certificate that does not have a mechanism to check its validity. This could be because the certificate revocation list is incorrect, unavailable, non existant or unreachable.
What you should do next?
Identify the offending certificate and discuss with your PKI SME regarding the validity of this cert, and why it does not have a validation mechanism.
Note that all other systems in scope of this GPO will have the same problem (regardless of being centrified or not).
R.P
Follow Centrify:



