Online Responding and CRL/AIA Discussion
dears,
i want discuss below points know best can done.
in environment, have below servers:
- root-ca: offline standalone root ca, crl/aia published locally , http://respond-01/, in aia have configured path online responding to: http://respond-01/ocsp
- respond-01: online server iis , online responding service role
- subordinate-01: online ca issuing server, configured default ldap crl/aia publishing, , online responding url to: http://respond-01/ocsp
i want disucss below:
- shall configure subordinate-01 crl , aia published respond-01? there need or best practice ask this?
- my online respond server ocsp certificate trusted root ca, shall change certificate trusted subordinate? there best practice point?
i recommend read post: http://en-us.sysadmins.lv/lists/posts/post.aspx?id=103
regarding ocsp: don't see practical reason use ocsp root cas.
vadims podāns, aka powershell cryptoguy
weblog: en-us.sysadmins.lv
powershell pki module: pspki.codeplex.com
powershell cmdlet editor pscmdlethelpeditor.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.
Windows Server > Security
Comments
Post a Comment