TSA server login method

Posted: 03/23/2012 08:21:21
by Vsevolod Ievgiienko (Team)

First of all try to remove certificateValidator_OnBeforeCRLRetrieverUse event handler. You shouldn't set authentication parameters for TElHTTPCRLRetriever because it doesn't connect to the TSA server. It connects to other servers that provide CRLs and usually doesn't require any authentication.

Second, you should add some kind of logging to TElX509CertificateValidator using its events to find out what is the reason of validation failure.
Posted: 03/23/2012 10:11:30
by ingbabic  (Standard support level)
Joined: 09/27/2011
Posts: 114

As I said the reason is 128, which would mean vrCRLNotVerified or Certificate Revocation List for this certificate could not be retrieved and/or validated.
Or you meant something else?
Posted: 03/23/2012 10:37:39
by Eugene Mayevski (Team)

Please re-read the article referenced above up to its end. There's a detailed description of the diagnostics procedure there, which I wrote in order that users wouldn't need to ask the same question again and again.

