Windows 10: How to to Add HTTP CRL locations to existing Machine Certificate template to automatically...

Discus and support How to to Add HTTP CRL locations to existing Machine Certificate template to automatically... in Windows 10 Gaming to solve the problem; Need to Add HTTP CRL locations to existing Machine Certificate template used to automatically issue certificates to workstations in MSPKI... Discussion in 'Windows 10 Gaming' started by Faiziyab Haider, Apr 28, 2025 at 3:22 PM.

  1. How to to Add HTTP CRL locations to existing Machine Certificate template to automatically...


    Need to Add HTTP CRL locations to existing Machine Certificate template used to automatically issue certificates to workstations in MSPKI

    :)
     
    Faiziyab Haider, Apr 28, 2025 at 3:22 PM
    #1
  2. 1one.w01f Win User

    Certificate Templates on the client side

    Hi,

    Good day to you all! I hope this is the right place to ask this.

    I have a few questions related to how certificate templates are being stored and distributed under AD CS:

    • How do the clients get a list of applicable certificate templates from the enterprise CA, which is shown at the time when a new manual certificate enrollment is performed (e.g., someone goes to certmgr and request for a new certificate)?
    • How are certificate templates being stored on both the CA side and the client side? Is there a directory that the templates reside in? Or are they just a collection of Windows registries (e.g. Software\Microsoft\Cryptography\CertificateTemplateCache
      under HKCU and HKLM)?
    • Is it possible to programmatically read and parse certificate templates on the client side, ideally via some Microsoft provided public API? I am asking this because sometimes it is useful to check, verify and debug that

      a) clients are getting all the expected templates;

      b) the content of templates are as expected (particularly useful if there were templates of duplicated names, or an old template has its setting changed but the name is kept);

      c) applicable clients are indeed getting the same list of templates.
    Please bear with me as I am a rookie to AD CS.

    Thanks!
     
  3. CRL caching behaviour of windows mobile 6.1 and Online Certificate Status Protocol (OCSP)

    Hi,

    Need information regarding CRL caching behaviour of windows mobile 6.1 and does it support Online Certificate Status Protocol (OCSP)?

    Many thanks for the help.

    -DK
     
    ideepakkumar, Apr 28, 2025 at 5:41 PM
    #3
  4. How to to Add HTTP CRL locations to existing Machine Certificate template to automatically...

    family safity blocks google.com, yotube.com

    On some machines, we have seen an issue where the Family Safety certificate installs, but the corresponding Certificate Revocation List (CRL) fails to install, and as a result all HTTPS websites are broken for your child account.

    You can work around the issue by turning off Web Filtering AND Web Activity Reporting for the child.

    If you want to fix the problem, you will need to delete the Family Safety certificate from the Trusted Root Certificate Authorities store for the local machine. This is not easy to get to, but here's how to do it:

    1. Follow the instructions on this page to open Certificate Manager for the Local Machine: https://technet.microsoft.com/en-us/library/cc754431.aspx#BKMK_computer

    2. Find the Trusted Root Certification Authorities folder. Verify that the Microsoft Family Safety certificate is present. If you don't see the Microsoft Family Safety certificate, stop; something else is causing your issue. (Or, you may have opened Certificate
    Manager for the current user, instead of for the "Local Machine". Check step 1 again.)

    3. Expand the Trusted Root Certification Authorities\Certificate Revocation Lists subfolder. If the folder is missing, or Microsoft Family Safety is not listed, then you are hitting this known issue. If you DO see the Microsoft Family Safety entry, then
    stop; something else is causing your issue.

    4. Once you have confirmed the diagnosis (Family Safety certificate is present, but CRL is missing), then go ahead and delete the Microsoft Family Safety certificate and reboot.

    5. The next time you log in with a child account, the certificate and CRL will be automatically re-created, and HTTPS websites should work.
     
    Daniel Strommen [MSFT], Apr 28, 2025 at 5:41 PM
    #4
Thema:

How to to Add HTTP CRL locations to existing Machine Certificate template to automatically...

Loading...
  1. How to to Add HTTP CRL locations to existing Machine Certificate template to automatically... - Similar Threads - Add HTTP CRL

  2. How to to Add HTTP CRL locations to existing Machine Certificate template to automatically...

    in Windows 10 Software and Apps
    How to to Add HTTP CRL locations to existing Machine Certificate template to automatically...: Need to Add HTTP CRL locations to existing Machine Certificate template used to automatically issue certificates to workstations in MSPKI https://answers.microsoft.com/en-us/windows/forum/all/how-to-to-add-http-crl-locations-to-existing/57a384e9-0ba8-4443-83a4-a089b4e37693
  3. how do I import an existing resume to a new template

    in Windows 10 Gaming
    how do I import an existing resume to a new template: I have an outdated resume, and I'd like to import my existing word doc so to a new template I can add to. https://answers.microsoft.com/en-us/windows/forum/all/how-do-i-import-an-existing-resume-to-a-new/e8714679-f53f-48ec-ad09-11af25614592
  4. how do I import an existing resume to a new template

    in Windows 10 Software and Apps
    how do I import an existing resume to a new template: I have an outdated resume, and I'd like to import my existing word doc so to a new template I can add to. https://answers.microsoft.com/en-us/windows/forum/all/how-do-i-import-an-existing-resume-to-a-new/e8714679-f53f-48ec-ad09-11af25614592
  5. accidentally deleted the CA certificate template

    in Windows 10 Gaming
    accidentally deleted the CA certificate template: Hi,When I was working on a certificate issue, I accidentally deleted a certificate template. This template is used by all windows servers and dcs. As I am still new to CA infrastructure and my senior who set up this is not available, I do not know what's the consequences...
  6. accidentally deleted the CA certificate template

    in Windows 10 Software and Apps
    accidentally deleted the CA certificate template: Hi,When I was working on a certificate issue, I accidentally deleted a certificate template. This template is used by all windows servers and dcs. As I am still new to CA infrastructure and my senior who set up this is not available, I do not know what's the consequences...
  7. How to add location to Favorites.

    in Windows 10 Gaming
    How to add location to Favorites.: I frequently need to upload image files to a website from a folder on my desktop named "Work". On the website when I click the button to do this, Windows opens a window named "File Upload". In the box on the right is "Documents library". I scroll down to the "Users" location....
  8. locating template

    in Windows 10 Network and Sharing
    locating template: I am trying to locate a document that I downloaded from the internet. It went into a file identified as TempState > Downloads. That folder does not come up when I hit Windows C: I can't find this folder in the normal folder pop up which has Windows C: Data D: , etc.....
  9. HTTP on my Win10 machine only?

    in Browsers and Email
    HTTP on my Win10 machine only?: I'm considering opening a website development section, a test-bed of sorts, on my Win10 machine, which is limited to my machine and does not connect to the WWW, and is only accessible from my machine. Is this doable? How easy it it to setup? Are there any easy-to-follow...
  10. HTTP on my Win10 machine only?

    in Windows 10 Support
    HTTP on my Win10 machine only?: I'm considering opening a website development section, a test-bed of sorts, on my Win10 machine, which is limited to my machine and does not connect to the WWW, and is only accessible from my machine. Is this doable? How easy it it to setup? Are there any easy-to-follow...