Is there a more imediate OCSP than the Microsoft Version compatible with AD CS


hello

i posted question on forum regarding crl v ocsp, vadims kindly answered of questions , made point ms version of ocsp still not immediate rather using element of caching (i assume take immediate strain off of ocsp , ca sever/s in high volume environments. wondering ocsp engine/server immediate e.g. each time requested check certificate goes ca database , reads current information revoked certificates last information each time, , if said ocsp engine/server compatible ad cs.

i did bit more reading on , understand ocsp using known 'providers' tell how/when information on revoked certificates etc. information read ms ocsp server has 1 provider default know , 'crl provider' which i believe means used (possibly all) settings regarding crl's decide how long should cache information , used for incoming certificate validation requests. therefore if reading information correctly explain vadims comment in previous post explain ms ocsp delayed service in similar way standard crl. in mind rather replacing ms ocsp thing else, possible change 'provider' ms ocsp uses make information if provides requests more date?

thanks all

aanotheruser__


aanotheruser__

> rather using element of caching

you incorrectly interpreted words. caching performed on client side. of course, windows ocsp server relies on crl , caches them. however, in revocation provider can configure period @ ocsp server reload crl urls specified in provider settings reduce latency. server side latency. however, ocsp puts ttl (time-to-live) in ocsp response equals referenced crl validity.

that is, ocsp server can refresh internal cache each 10 minutes. when client queries ocsp, receives recent response. response's validity relatively long (until referenced crl expires) , ocsp cached time.

if looking direct ca database query, should take @ 3rd party solutions. example, tumbleweed/axway ocsp server.

> in mind rather replacing ms ocsp thing else, possible change 'provider' ms ocsp uses make information if provides requests more date?

a time ago talked ocsp developers custom providers. although, windows ocsp written support external revocation providers, never made provider interfaces public. answer no, there no way write custom provider use ca database (for example) revocation status detection.


my weblog: en-us.sysadmins.lv
powershell pki module: pspki.codeplex.com
powershell cmdlet editor pscmdlethelpeditor.codeplex.com
check out new: ssl certificate verifier
check out new: powershell fciv tool.



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS