Can OCSP Responder Cacheing be "Avoided"?


hello,
i've deployed online responder service in hope of getting fresher responses failing; environment 2008 ad, r2 enterprise subordinate cas , r2 online responders.

background: have 3 day crl + 3 day overlap (i want give me breathing space in case of ca failure).  on top of this, publish fresh crl every time certificate revoked.  i have set online responder retrieve crls every thirty minutes such "latest crls" used responder generating responses. 

however, aware online responder caches crls authoritative period , therefore won't bother using newer crl.  i can understand many circumstances totally sensible behaviour (performance, etc.) - situation i'd "force" responder use new crl.  this way i'd have "long crl" stop me having headache of ca failures, whilst having recent revocation status pushed out responder.

can give me advice on whether want achieve possible?  i've used tumbleweed validation authority in past , kind of thing not problem configure hoping can similar windows.

thanks, brian

because ocsp responder uses crls determine ocsp response, crl caching cannot turned off
i know many customers have made feature request, now, think of ocsp responses ms responder mini-crls
you need rething 3 day crl 3 day overlap design , come better method deal ca failure , crl publication
brian


Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS