CRL configuration
hello,
situation. within our company want solid configuration our crl availability without risc of downtime crl isn't available. configuration follows:
system configuration: windows 2008r2
every intermediate ca creates every hour crl, valid 4 hours. make copy of crl , resign validity period of 7 days (just simple certutil command).
both crls have of course diferent names , checked again , pushed 2 webservers , published there. done every hour.
in our certificates use of short crl (4 hours) stated first , second 7 days crl.
if reason crls aren't published in time , short crl not valid anymore, checking done against 7 days crl , 1 localy cached on clients. if things went , crl publishing fixed, clients automatically return short crl after 7 days.
in past looked @ possibility delta crls, not option because:
use different environment (linux, zos, ..) doesn't support delta's
if base crl of delta crl file reason corrupt of not available whole crl checking failed. in our configuration in case checking switches second crl in line.
this counts our configuration of ocsp. can use 2 crls within ocsp providers, somehow windows reacts not quit expected crl refresh-rate within ocsp configuration.
question: not standard microsoft solution , based on internal written software. looking configuration gives same amout of availability, fits standard configuration of microsoft. crls , ocsp should available across different platforms.
according description, understanding need configuration of microsoft crls , ocsp available across different platforms.
since configuration includes multi products, , there no specific error, based on current test environment, difficult reproduce or test environment have mentioned.
below blog ocsp(more parts linked in blog), including introduction , detailed configuration steps, reference:
http://blogs.technet.com/b/askds/archive/2009/06/24/implementing-an-ocsp-responder-part-i-introducing-ocsp.aspx
best regards,
eve wang
please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.
Windows Server > Windows Server General Forum
Comments
Post a Comment