Certificate renewal period being ignored (OCSP)
I have a Windows 2008 OCSP responder that is automatically renewing it's signing certificate (from an Enterprise 2008 CA) every 2 days, despite the template having a lifetime of a year and a renewal period of 6 weeks (yes I know that is considered too long, has to be that way). When the OCSP service was first installed the template had a very short lifetime with a renewal period of two days, however it's subsequently been extended. The provider has been deleted and re-added, but it won't honor the new renewal periods. The CA stopped offering the template, then re added it. In between re-adding an OCSP provider any old certs have been deleted (from the service account). Any ideas what could be happening?
January 24th, 2012 1:35pm

After you edit the template, you have to re-enroll all certificate holders http://technet.microsoft.com/en-us/library/cc771246(WS.10).aspx
Free Windows Admin Tool Kit Click here and download it now
January 30th, 2012 12:38am

Unfortunately that didn't make any difference, still ignoring the values and renewing every two days...
February 2nd, 2012 12:01pm

Try setting up the OCSP configuration anew, if you are using autoenroll of the certificate. Think I had a similar thing happen in the lab onetime, though it went away after I configured the OCSP anew. Just a though :)
Free Windows Admin Tool Kit Click here and download it now
February 3rd, 2012 2:38am

I've set up the OCSP configuration for this provider many times. The only thing i have left to try is to completely remove the service and install it again, but that seems a little drastic.
February 3rd, 2012 11:16am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics