August 2019
Intermediate to advanced
786 pages
20h 22m
English
AIA is an extension that is in the certificate and defines the location where the application or the service can retrieve the issuing CA's certificate. This is also a web-based path, and we can use the same location we used for the CDP.
AIA location can be set using the following command:
certutil -setreg CA\CACertPublicationURLs "1:C:\Windows\system32\CertSrv\CertEnroll\%1_%3%4.crt\n2:ldap:///CN=%7,CN=AIA,CN=Public Key Services,CN=Services,%6%11\n2:http://crt.rebeladmin.com/CertEnroll/%1_%3%4.crt"
The options are very much similar to those for the CDP, with a few small changes:
|
Option |
Details |
|
0 |
No changes. |
|
1 |
Publish CA certificate to a given location. |
|
2 |
Attach AIA extensions of issued certificates. |