{"id":297,"date":"2013-03-07T23:30:42","date_gmt":"2013-03-08T07:30:42","guid":{"rendered":"http:\/\/unmitigatedrisk.com\/?p=297"},"modified":"2013-03-22T00:53:28","modified_gmt":"2013-03-22T08:53:28","slug":"advanced-troubleshooting-of-certificate-validation-related-problems-on-windows-part-1","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=297","title":{"rendered":"Advanced Troubleshooting of Certificate Validation Related Problems on Windows Part 1"},"content":{"rendered":"<p>The Windows platform for validating X.509 certificates has a feature I don\u2019t see many discuss &#8212; its robust logging subsystem.<\/p>\n<p>This allows a non-developer (and developers) to get insights into what is happening with applications interactions with CryptoAPI 2 and to some degree what is happening inside those APIs.<\/p>\n<p>To use this feature you must first enable it, the easiest way to do that is via the EventViewer Management Console (eventvwr.msc), once in there you must navigate to the CryptoAPI 2 (CAPI2) node of the viewer:<\/p>\n<table width=\"586\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"247\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image0016.png\"><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px; display: inline; background-image: none;\" title=\"clip_image001[6]\" alt=\"clip_image001[6]\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image0016_thumb.png\" width=\"244\" height=\"227\" border=\"0\" \/><\/a><\/td>\n<td valign=\"top\" width=\"169\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image0026.png\"><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px; display: inline; background-image: none;\" title=\"clip_image002[6]\" alt=\"clip_image002[6]\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image0026_thumb.png\" width=\"166\" height=\"244\" border=\"0\" \/><\/a><\/td>\n<td valign=\"top\" width=\"168\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image0036.png\"><img loading=\"lazy\" decoding=\"async\" style=\"display: inline; background-image: none;\" title=\"clip_image003[6]\" alt=\"clip_image003[6]\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image0036_thumb.png\" width=\"165\" height=\"244\" border=\"0\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>Once you get there you select Properties on the operational log, which will give you a dialog that looks something like this:<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image007.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px; display: inline; background-image: none;\" title=\"clip_image007\" alt=\"clip_image007\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image007_thumb.jpg\" width=\"244\" height=\"230\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Once you \u201cEnable Logging\u201d and \u201cApply\u201d the changes, immediately all calls to CryptoAPI will be logged. CryptoAPI is used all the time so by the time you close that dialog you will have some events you can look at:<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image008.png\"><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px; display: inline; background-image: none;\" title=\"clip_image008\" alt=\"clip_image008\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image008_thumb.png\" width=\"244\" height=\"146\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>The high level view of each event doesn\u2019t tell you much, for example in the above picture we really only know that the action that was being performed with a \u201cBuild Chain\u201d, this particular event corresponds to a call to <a href=\"http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa376078(v=vs.85).aspx\">CertGetCertificateChain<\/a>.<\/p>\n<p>To really understand what is going on you need to look at the Details tab:<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image009.png\"><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px; display: inline; background-image: none;\" title=\"clip_image009\" alt=\"clip_image009\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image009_thumb.png\" width=\"244\" height=\"176\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Here we can see what was passed into a given into that API call, we can see what certificates we passed in by the calling application, what settings they chose when making that call:<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image011.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px; display: inline; background-image: none;\" title=\"clip_image011\" alt=\"clip_image011\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image011_thumb.jpg\" width=\"244\" height=\"71\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Some other things you can see in this particular API call include what the disposition of the call was and of course what certificate chain was built.<\/p>\n<p>Every major API in CryptoAPI has logging similar to this, you get to see what is passed in and what came out. Additionally major \u201cobjects\u201d are sometimes logged as well, for example here is an event showing a certificate that CryptoAPI was operating against:<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image012.png\"><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px; display: inline; background-image: none;\" title=\"clip_image012\" alt=\"clip_image012\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image012_thumb.png\" width=\"244\" height=\"31\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Another very useful API to be able to look at is <a href=\"http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa377167(v=vs.85).aspx\">CertVerifyRevocation<\/a>, this will be logged in this fashion:<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image013.png\"><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px; display: inline; background-image: none;\" title=\"clip_image013\" alt=\"clip_image013\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image013_thumb.png\" width=\"244\" height=\"35\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Some of these events include references to temporary files, for example in this case you see:<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image014.png\"><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px; display: inline; background-image: none;\" title=\"clip_image014\" alt=\"clip_image014\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image014_thumb.png\" width=\"244\" height=\"47\" border=\"0\" \/><\/a><\/p>\n<p>This is a CRL for the \u201cGlobalSign PersonalSign 1 CA \u2013 G2\u201d, its stored in the Time Valid Object Cahce (TvoCache), you can look at this cache with the \u201ccertutil \u2013urlcache\u201d command.<\/p>\n<p>&nbsp;<\/p>\n<p>The events will all tell you which application was the caller and if they are part of a sequence of tasks you get enough information to correlate them and put them in order.<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image015.png\"><img loading=\"lazy\" decoding=\"async\" style=\"display: inline; background-image: none;\" title=\"clip_image015\" alt=\"clip_image015\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2013\/03\/clip_image015_thumb.png\" width=\"244\" height=\"82\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>I won\u2019t go through all of the events but as you can see this is super valuable when trying to figure out \u2013 Why did that application do that?!<\/p>\n<p>As you might imagine this logging can slow things down and produces a bunch of data so be sure to turn it off when you are done.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Windows platform for validating X.509 certificates has a feature I don\u2019t see many discuss &#8212; its robust logging subsystem. This allows a non-developer (and developers) to get insights into what is happening with applications interactions with CryptoAPI 2 and to some degree what is happening inside those APIs. To use this feature you must [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[12,3],"tags":[36,24,79,80],"class_list":["post-297","post","type-post","status-publish","format-standard","hentry","category-programming","category-security","tag-cryptoapi","tag-revocation","tag-troubleshooting","tag-x-509"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/297","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=297"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/297\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=297"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=297"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=297"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}