%3CLINGO-SUB%20id%3D%22lingo-sub-1128386%22%20slang%3D%22en-US%22%3EA%20simple%20way%20to%20set%20the%20certutil%20-config%20option%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1128386%22%20slang%3D%22en-US%22%3E%0A%20%26lt%3Bmeta%20http-equiv%3D%22Content-Type%22%20content%3D%22text%2Fhtml%3B%20charset%3DUTF-8%22%20%2F%26gt%3B%3CSTRONG%3E%20First%20published%20on%20TECHNET%20on%20May%2012%2C%202007%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3E%3CP%20class%3D%22MsoNormal%22%20style%3D%22MARGIN%3A%200cm%200cm%2010pt%3B%20LINE-HEIGHT%3A%20normal%22%3E%3CSPAN%20lang%3D%22en-us%22%20style%3D%22FONT-SIZE%3A%2010pt%3B%20COLOR%3A%20%2331849b%3B%20FONT-FAMILY%3A%20'Lucida%20Sans%20Unicode'%2C'sans-serif'%3B%20mso-themecolor%3A%20accent5%3B%20mso-themeshade%3A%20191%3B%20mso-ansi-language%3A%20EN-US%3B%20mso-fareast-font-family%3A%20'Times%20New%20Roman'%3B%20mso-fareast-language%3A%20DE%22%3E%20When%20you%20are%20performing%20an%20operation%20on%20a%20remote%20CA%2C%20certutil%20requires%20the%20config%20string%20as%20input%20parameter.%20The%20common%20way%20to%20find%20out%20the%20config%20string%20is%20to%20run%20a%20%3C%2FSPAN%3E%20%3CSPAN%20lang%3D%22en-us%22%20style%3D%22FONT-SIZE%3A%208pt%3B%20COLOR%3A%20black%3B%20FONT-FAMILY%3A%20'Courier%20New'%3B%20mso-themecolor%3A%20text1%3B%20mso-ansi-language%3A%20EN-US%22%3E%20certutil%20-dump%20%3C%2FSPAN%3E%20%3CSPAN%20lang%3D%22en-us%22%20style%3D%22FONT-SIZE%3A%2010pt%3B%20COLOR%3A%20%2331849b%3B%20FONT-FAMILY%3A%20'Lucida%20Sans%20Unicode'%2C'sans-serif'%3B%20mso-themecolor%3A%20accent5%3B%20mso-themeshade%3A%20191%3B%20mso-ansi-language%3A%20EN-US%3B%20mso-fareast-font-family%3A%20'Times%20New%20Roman'%3B%20mso-fareast-language%3A%20DE%22%3E%20command%2C%20list%20all%20available%20CAs%20in%20the%20Active%20Directory%20forest%20and%20copy%2Fpast%20the%20config%20parameter%20from%20the%20dump%20into%20the%20new%20command-line.%20%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3C%2FP%3E%0A%20%20%20%0A%20%20%3CP%3E%3C%2FP%3E%3CBR%20%2F%3E%3CP%20class%3D%22MsoNormal%22%20style%3D%22MARGIN%3A%200cm%200cm%2010pt%3B%20LINE-HEIGHT%3A%20normal%22%3E%3CSPAN%20lang%3D%22en-us%22%20style%3D%22FONT-SIZE%3A%2010pt%3B%20COLOR%3A%20%2331849b%3B%20FONT-FAMILY%3A%20'Lucida%20Sans%20Unicode'%2C'sans-serif'%3B%20mso-themecolor%3A%20accent5%3B%20mso-themeshade%3A%20191%3B%20mso-ansi-language%3A%20EN-US%3B%20mso-fareast-font-family%3A%20'Times%20New%20Roman'%3B%20mso-fareast-language%3A%20DE%22%3E%20There%20is%20a%20much%20simpler%20way%20to%20set%20the%20config%20string%20in%20certutil.%20Just%20use%20a%20dash%20as%20config%20string%20and%20certutil%20will%20show%20a%20selection%20dialog%20with%20all%20CAs%20that%20are%20registered%20in%20your%20Active%20Directory%20forest.%20%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3C%2FP%3E%0A%20%20%20%0A%20%20%3CP%3E%3C%2FP%3E%3CBR%20%2F%3E%3CP%20class%3D%22MsoNormal%22%20style%3D%22MARGIN%3A%200cm%200cm%2010pt%3B%20LINE-HEIGHT%3A%20normal%22%3E%3CSPAN%20lang%3D%22en-us%22%20style%3D%22FONT-SIZE%3A%2010pt%3B%20COLOR%3A%20%2331849b%3B%20FONT-FAMILY%3A%20'Lucida%20Sans%20Unicode'%2C'sans-serif'%3B%20mso-themecolor%3A%20accent5%3B%20mso-themeshade%3A%20191%3B%20mso-ansi-language%3A%20EN-US%3B%20mso-fareast-font-family%3A%20'Times%20New%20Roman'%3B%20mso-fareast-language%3A%20DE%22%3E%20For%20example%20to%20verify%20the%20responsiveness%20of%20a%20remote%20CA%2C%20run%20the%20following%20command%20and%20select%20the%20target%20CA%20from%20the%20list%20of%20available%20CAs.%20%3C%2FSPAN%3E%3C%2FP%3E%3CBR%20%2F%3E%3CP%20class%3D%22MsoNormal%22%20style%3D%22MARGIN%3A%200cm%200cm%2010pt%3B%20LINE-HEIGHT%3A%20normal%22%3E%3CSPAN%20lang%3D%22en-us%22%20style%3D%22FONT-SIZE%3A%208pt%3B%20COLOR%3A%20black%3B%20FONT-FAMILY%3A%20'Courier%20New'%3B%20mso-themecolor%3A%20text1%3B%20mso-ansi-language%3A%20EN-US%22%3E%20certutil%20%E2%80%93config%20-%20-ping%20%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3C%2FP%3E%0A%20%20%20%0A%20%20%3CP%3E%3C%2FP%3E%0A%20%0A%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1128386%22%20slang%3D%22en-US%22%3EFirst%20published%20on%20TECHNET%20on%20May%2012%2C%202007%20When%20you%20are%20performing%20an%20operation%20on%20a%20remote%20CA%2C%20certutil%20requires%20the%20config%20string%20as%20input%20parameter.%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1128386%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Ecertutil%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

First published on TECHNET on May 12, 2007

When you are performing an operation on a remote CA, certutil requires the config string as input parameter. The common way to find out the config string is to run a certutil -dump command, list all available CAs in the Active Directory forest and copy/past the config parameter from the dump into the new command-line.

 

 

 

There is a much simpler way to set the config string in certutil. Just use a dash as config string and certutil will show a selection dialog with all CAs that are registered in your Active Directory forest.

 

 

 

For example to verify the responsiveness of a remote CA, run the following command and select the target CA from the list of available CAs.

 

certutil –config - -ping