XADM: KM Server Issues V1 Certificate When Configured to Issue V3 Only

ID: Q231307


The information in this article applies to:


SYMPTOMS

If you configure a Key Management (KM) server to issue X.509 V3 certificates only, the server may still issue V1 certificates when e-mail clients request them. This problem is known to occur with the Microsoft Exchange client versions 4.0 and 5.0, and Microsoft Outlook 97, but the problem can occur with any e-mail client that only uses V1 certificates.


CAUSE

When an e-mail client requests a certificate from a KM server, the server does not verify that the request is compatible with its current configuration.


RESOLUTION

A supported fix that corrects this problem is now available from Microsoft, but it has not been fully regression tested and should be applied only to systems experiencing this specific problem. If you are not severely affected by this specific problem, Microsoft recommends that you wait for the next Microsoft Exchange Server version 5.5 service pack that contains this fix.

To resolve this problem immediately, contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information on support costs, please go to the following address on the World Wide Web:

http://www.microsoft.com/support/supportnet/overview/overview.asp
Component: Key Management

File name Version
Kmserver.exe 5.5.2606.0
Kmsmsg.dll 5.5.2606.0


NOTE: If this product was already installed on your computer when you purchased it from the Original Equipment Manufacturer (OEM) and you need this fix, please call the Pay Per Incident number listed on the above Web site. If you contact Microsoft to obtain this fix, and if it is determined that you only require the fix you requested, no fee will be charged. However, if you request additional technical support, and if your no-charge technical support period has expired, or if you are not eligible for standard no-charge technical support, you may be charged a non-refundable fee.

For more information about eligibility for no-charge technical support, see the following article in the Microsoft Knowledge Base:
Q154871 Determining If You Are Eligible for No-Charge Technical Support


STATUS

Microsoft has confirmed this to be a problem in Microsoft Exchange Server version 5.5.

Additional query words:


Keywords          : 
Version           : winnt:5.5
Platform          : winnt 
Issue type        : kbbug 

Last Reviewed: June 28, 1999