Certificate renewal period being ignored (OCSP)
I have a Windows 2008 OCSP responder that is automatically renewing it's signing certificate (from an Enterprise 2008 CA) every 2 days, despite the template having a lifetime of a year and a renewal period of 6 weeks (yes I know that is considered
too long, has to be that way).
When the OCSP service was first installed the template had a very short lifetime with a renewal period of two days, however it's subsequently been extended. The provider has been deleted and re-added, but it won't honor the new renewal periods.
The CA stopped offering the template, then re added it.
In between re-adding an OCSP provider any old certs have been deleted (from the service account).
Any ideas what could be happening?
January 24th, 2012 1:35pm
After you edit the template, you have to re-enroll all certificate holders
http://technet.microsoft.com/en-us/library/cc771246(WS.10).aspx
Free Windows Admin Tool Kit Click here and download it now
January 30th, 2012 12:38am
Unfortunately that didn't make any difference, still ignoring the values and renewing every two days...
February 2nd, 2012 12:01pm
Try setting up the OCSP configuration anew, if you are using autoenroll of the certificate.
Think I had a similar thing happen in the lab onetime, though it went away after I configured the OCSP anew.
Just a though :)
Free Windows Admin Tool Kit Click here and download it now
February 3rd, 2012 2:38am
I've set up the OCSP configuration for this provider many times. The only thing i have left to try is to completely remove the service and install it again, but that seems a little drastic.
February 3rd, 2012 11:16am