nerdexam
Microsoft

70-642 · Question #295

Your network contains an Active Directory domain named Contoso.com. Contoso.com contains an enterprise certification authority (CA) named CA1. You enable Secure Socket Tunneling Protocol (SSTP) on a…

The correct answer is B. Publish the certificate revocation list distribution point (CDP) to a location that is accessible. Client tries to connect to SSTP VPN server and it fails to connect giving error message Trouble-shooting steps: This will happen if client is failing the certificate revocation check of the SSL certificate obtained from server side. Ensure the CRL check servers on the server…

Configuring Routing and Remote Access

Question

Your network contains an Active Directory domain named Contoso.com. Contoso.com contains an enterprise certification authority (CA) named CA1. You enable Secure Socket Tunneling Protocol (SSTP) on a server named Server1. A user named User1 attempts to establish an SSTP connection to Server1 and receives the following error message:

Error 0x80092013: The revocation function was unable to check revocation because the revocation server was offline. You verify that all certificates services are online. You need to ensure that User1 can connect to Server1 by using SSTP. What should you do first?

Options

  • AConfigure a pre-shared key for IPSec on User1s computer.
  • BPublish the certificate revocation list distribution point (CDP) to a location that is accessible
  • CConfigure User1 for certificate autoenrollment.
  • DAdd a certificate to Server1 that contains server1.contoso.com as a Subject Alternative

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    81% (25)
  • C
    6% (2)
  • D
    10% (3)

Explanation

Client tries to connect to SSTP VPN server and it fails to connect giving error message Trouble-shooting steps: This will happen if client is failing the certificate revocation check of the SSL certificate obtained from server side. Ensure the CRL check servers on the server side are exposed on the Internet. This is because CRL check is done on the client side during SSL connection establishment phase and the CRL check query will be directly going on the Internet.

Topics

#SSTP VPN#certificate revocation list#CDP distribution point#PKI

Community Discussion

No community discussion yet for this question.

Full 70-642 Practice