10. Install and Configure the OCSP Responder Role service

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024
  • Video Series on Managing Active Directory Certificate Services:
    Part-5: In the fifth part of this six part video series on how to deploy a Two-Tier Public Key Infrastructure, we will see the steps on how to install and configure an Online Responder Server role on Windows Server 2019 web server. To finalize the configuration of an online responder, you must configure and install an OCSP Response Signing certificate and configure an Authority Information Access extension to support it. After this is done, you must assign the template to a CA and then enroll the system to obtain the certificate.
    Click Here to see the Next part:
    • 11. Verify PKI health...
    Full Playlist:
    yt.vu/p/PLUZTRm...
    Follow my blogs:
    msftwebcast.bl...

Комментарии • 25

  • @mus2007
    @mus2007 2 года назад +1

    Thanks a lot for these vedeos, very helpfull

  • @kamaljeetsingh3778
    @kamaljeetsingh3778 3 года назад +2

    Excellent Sir !!!

  • @matthewbishop89
    @matthewbishop89 Год назад +1

    Great tutorial, I was having issues until you shared the steps to revoke CA Exchange and issue new one. Next, trying to figure out why custom template is not getting displayed in dropdown.

  • @zyzzzyzz105
    @zyzzzyzz105 Год назад +1

    Lot of learning bro ❤️

  • @wisher77
    @wisher77 4 года назад +1

    in the revocation provider properties no http base crl appears, only a ldap base crl is there. How would i manually add a http base crl or what am I doing wrong that it isn't automatically there?

  • @_trust9994
    @_trust9994 2 года назад +1

    Thanks my friend!

  • @davidburic538
    @davidburic538 3 года назад +1

    Hello, thanks a lot for these videos. I have one question regarding the 2-tier pki. If I have two subordinate CAs, is it possible to have just one OCSP transponder? I mean, if both my subordinate CAs would have the AIA configured to the same URL/host, which would "host" the configuration for both?

  • @LakshmiNarayanaRao.V
    @LakshmiNarayanaRao.V 5 лет назад +2

    Hello,
    Please create video on renewing Subordinate and OCSP renewal process. Its not there anywhere in RUclips or Internet.

  • @imaneziad8827
    @imaneziad8827 2 месяца назад

    I can't find OCSP response signing in Enable Certificate Templates, what can be the problem?

  • @hariclassic8235
    @hariclassic8235 16 дней назад

    My CDP and AIA location is not working either with server fqdn or web name fqdn, Can you help?

  • @iamneo8115
    @iamneo8115 3 года назад

    you are the best!

  • @nandalgmovie
    @nandalgmovie 2 года назад

    Are we saying even the OCSP server also have certificate Authority and Certificate Authority Web enrollment installed. I thought we need to install certificate Authority and Certificate Authority Web enrollment only in the CA server. Please clarify

  • @anuchaub26
    @anuchaub26 3 года назад

    If I don't have server. Can i create certificate add ocsp ?

  • @ahmedsaad-lk2og
    @ahmedsaad-lk2og 2 года назад

    thanks

  • @jeffer8762
    @jeffer8762 4 года назад

    what is the CA exchange template for ?

    • @MSFTWebCast
      @MSFTWebCast  4 года назад

      CA Exchange certificate is used by key archival process.

    • @jeffer8762
      @jeffer8762 4 года назад

      @@MSFTWebCast so the step for CA Exchange certificate template is necessary ?

    • @MSFTWebCast
      @MSFTWebCast  4 года назад

      @@jeffer8762 yes.

    • @fbifido2
      @fbifido2 3 года назад +2

      @@MSFTWebCast The Issuing server don't have CA exchange Template, so how does it give it out?
      I can see only 2 templates on this server: User & OCSP Responder.
      Do you need to add computer, domain controller, web server, etc ... what is the minimum template to fully make ADCS work properly ?

  • @GTGeek88
    @GTGeek88 11 месяцев назад

    Wow, the accent makes it really hard to understand.

    • @MSFTWebCast
      @MSFTWebCast  11 месяцев назад

      My bad, apologies but thats how I sound.

    • @samuel-ff2sl
      @samuel-ff2sl 7 месяцев назад +1

      It doesn't and this comment is unnecessarily rude.

    • @RabidMullet
      @RabidMullet 6 месяцев назад +1

      @@samuel-ff2sl Agreed. This was incredibly helpful and not hard understand at all.