根证书自动从“受信任的根证书颁发机构”中删除
我有一个带有测试公钥基础设施的开发环境。该基础设施具有一个根 CA、一个中间 CA 和多个终端实体(客户端和服务器)。 在开发人员上。计算机上,根 CA 安装到“受信任的根证书颁发机构”中,模拟“商业受信任的 CA”
我过去曾多次成功使用此环境,但是我目前观察到以下行为:根 CA 是第一次构建使用它的链(例如 SSL 连接建立)时,会自动从“受信任的根证书颁发机构”中删除。
我知道Windows会自动将证书添加到“受信任的根证书颁发机构”。但是,我不知道它们可以自动删除。在什么情况下会发生这种删除?
根证书不指向 CRL 也不指向 OCSP 端点。
谢谢
佩德罗
I've a development environment with a test public key infrastructure. This infrastructure has one root CA, one intermediate CA and multiple end-entities (clients and servers).
On the dev. machines, the root CA is installed into the "Trusted Root Certification Authorities", simulating a "commercial trusted CA"
I've successfully used this environment several times in the past, however I'm currently observing the following behavior: the root CA is automatically removed from the "Trusted Root Certification Authorities" the first time a chain using it is built (e.g. SSL connection establishment).
I know that windows automatically adds certificates to the "Trusted Root Certification Authorities". However, I didn't knew that they could be automatically removed. What are the circumstances on which this removal can happen?
The root certificate doesn't point to a CRL nor to a OCSP endpoint.
Thanks
Pedro
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论