Hi,
I am importing a public certificate at Exchange.
I am using powershell (there are no errors. Using a .pfx certificate exported from .cer certificate wich was bought from public CA):
but at ECP The error is the following: Revocation check failed.
The command certutil -verify -urlfetch "C:\Certificado\Certificado.cer" is OK:
C:\Windows\system32>certutil -verify -urlfetch "C:\Certificado\Certificado.cer"
Issuer:
CN=Symantec Class 3 EV SSL CA - G2
OU=Symantec Trust Network
O=Symantec Corporation
C=US
Name Hash(sha1): 3e318430d317e5e4c1cbd83e5242b6268e126e8c
Name Hash(md5): 175aa39120eb516b9f2fdb2a5b9df9fb
Subject:
CN=webmail.mycompany.com
OU=IT
O=MYCOMPANY S.A
L=Quito
S=Pichincha
C=EC
SERIALNUMBER=1790368718001
OID.2.5.4.15=Private Organization
OID.1.3.6.1.4.1.311.60.2.1.3=EC
Name Hash(sha1): 53bf650fb55f4a72fd6e9e5a46102052c15839aa
Name Hash(md5): 7f4ed8132113e3910f1804ba1af7b79d
Cert Serial Number: 30e99b2ba418619514428fc704151007
dwFlags = CA_VERIFY_FLAGS_CONSOLE_TRACE (0x20000000)
dwFlags = CA_VERIFY_FLAGS_DUMP_CHAIN (0x40000000)
ChainFlags = CERT_CHAIN_REVOCATION_CHECK_CHAIN_EXCLUDE_ROOT (0x40000000)
HCCE_LOCAL_MACHINE
CERT_CHAIN_POLICY_BASE
-------- CERT_CHAIN_CONTEXT --------
ChainContext.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
ChainContext.dwRevocationFreshnessTime: 2 Days, 3 Hours, 21 Minutes, 9 Seconds
SimpleChain.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
SimpleChain.dwRevocationFreshnessTime: 2 Days, 3 Hours, 21 Minutes, 9 Seconds
CertContext[0][0]: dwInfoStatus=102 dwErrorStatus=0
Issuer: CN=Symantec Class 3 EV SSL CA - G2, OU=Symantec Trust Network, O=Syman
tec Corporation, C=US
NotBefore: 8/25/2014 7:00 PM
NotAfter: 3/23/2015 6:59 PM
Subject: CN=webmail.mycompany.com, OU=IT, O=MYCOMPANY S.A, L=Quito, S=Pichincha, C=EC, SERIALNUMBER=1790368718001, OID.2.5.4.15=Priv
ate Organization, OID.1.3.6.1.4.1.311.60.2.1.3=EC
Serial: 30e99b2ba418619514428fc704151007
SubjectAltName: DNS Name=autodiscover.mycompany.com, DNS Name=webmail.mycompany.com
a1837ff142db4a6b34f1cac3b2e31536d91cb4cc
Element.dwInfoStatus = CERT_TRUST_HAS_KEY_MATCH_ISSUER (0x2)
Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
---------------- Certificate AIA ----------------
Verified "Certificate (0)" Time: 0
[0.0] http://st.symcb.com/st.crt
---------------- Certificate CDP ----------------
Verified "Base CRL (023b)" Time: 0
[0.0] http://st.symcb.com/st.crl
---------------- Base CRL CDP ----------------
No URLs "None" Time: 0
---------------- Certificate OCSP ----------------
Verified "OCSP" Time: 0
[0.0] http://st.symcd.com
--------------------------------
CRL (null):
Issuer: CN=Symantec Class 3 EV SSL CA - G2 OCSP Responder
ThisUpdate: 9/7/2014 7:44 PM
NextUpdate: 9/14/2014 7:44 PM
4dcd9e2be70b835fe09bb6314aaae1d03978e0ad
Issuance[0] = 2.16.840.1.113733.1.7.23.6
Application[0] = 1.3.6.1.5.5.7.3.1 Server Authentication
Application[1] = 1.3.6.1.5.5.7.3.2 Client Authentication
CertContext[0][1]: dwInfoStatus=102 dwErrorStatus=0
Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G5, OU="(
c) 2006 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O=
"VeriSign, Inc.", C=US
NotBefore: 10/30/2013 7:00 PM
NotAfter: 10/30/2023 6:59 PM
Subject: CN=Symantec Class 3 EV SSL CA - G2, OU=Symantec Trust Network, O=Syma
ntec Corporation, C=US
Serial: 366585077a8867ab58f4a094f8103733
SubjectAltName: Directory Address:CN=SymantecPKI-1-532
3a823e0346b921b59b75ac2dbdac36b3a45999e4
Element.dwInfoStatus = CERT_TRUST_HAS_KEY_MATCH_ISSUER (0x2)
Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
---------------- Certificate AIA ----------------
No URLs "None" Time: 0
---------------- Certificate CDP ----------------
Verified "Base CRL" Time: 0
[0.0] http://s1.symcb.com/pca3-g5.crl
---------------- Base CRL CDP ----------------
No URLs "None" Time: 0
---------------- Certificate OCSP ----------------
Verified "OCSP" Time: 0
[0.0] http://s2.symcb.com
--------------------------------
CRL (null):
Issuer: CN=Symantec Class 3 PCA - G5 OCSP Responder Certificate 2, OU=Symant
ec Trust Network, O=Symantec Corporation, C=US
ThisUpdate: 9/6/2014 12:29 PM
NextUpdate: 9/13/2014 12:29 PM
b36ad52fbaa0be055fbeec58494ecdef90b9dd6d
Application[0] = 1.3.6.1.5.5.7.3.1 Server Authentication
Application[1] = 1.3.6.1.5.5.7.3.2 Client Authentication
Application[2] = 1.3.6.1.5.5.7.3.4 Secure Email
Application[3] = 1.3.6.1.5.5.7.3.3 Code Signing
CertContext[0][2]: dwInfoStatus=10c dwErrorStatus=0
Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G5, OU="(
c) 2006 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O=
"VeriSign, Inc.", C=US
NotBefore: 11/7/2006 7:00 PM
NotAfter: 7/16/2036 6:59 PM
Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G5, OU="
(c) 2006 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O
="VeriSign, Inc.", C=US
Serial: 18dad19e267de8bb4a2158cdcc6b3b4a
e5a544679b3dbe56ad1e585fcf1c9b4978d5b64e
Element.dwInfoStatus = CERT_TRUST_HAS_NAME_MATCH_ISSUER (0x4)
Element.dwInfoStatus = CERT_TRUST_IS_SELF_SIGNED (0x8)
Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)
---------------- Certificate AIA ----------------
No URLs "None" Time: 0
---------------- Certificate CDP ----------------
No URLs "None" Time: 0
---------------- Certificate OCSP ----------------
No URLs "None" Time: 0
--------------------------------
Application[0] = 1.3.6.1.5.5.7.3.1 Server Authentication
Application[1] = 1.3.6.1.5.5.7.3.2 Client Authentication
Application[2] = 1.3.6.1.5.5.7.3.4 Secure Email
Application[3] = 1.3.6.1.5.5.7.3.3 Code Signing
Exclude leaf cert:
dc7078536d1a738b48eb6dddae133de0150626e9
Full chain:
1ceb396aff8853ef35fade8d8f5ec68483fbdc55
------------------------------------
Verified Issuance Policies:
2.16.840.1.113733.1.7.23.6
Verified Application Policies:
1.3.6.1.5.5.7.3.1 Server Authentication
1.3.6.1.5.5.7.3.2 Client Authentication
Cert is an End Entity certificate
Leaf certificate revocation check passed
CertUtil: -verify command completed successfully.
The question is:
How to successfully import the public certificate at Exchange?
Thanks in advance for your valuable help!