IIS hardening for OCSP

Anonymous
2024-11-26T10:28:23+00:00

Hello

we are providing OCSP (Microsoft) services which run on IIS.

In the process of hardening IIS the following findings have surfaced. May I ask for your input since the Internet does not provide any information:

  • Ensure global .Net trust level is configured

Does OSCP utilize .Net? Which .Net trust level is needed

  • Ensure unlisted file extensions are not allowed

Which file extensions does OCSP need to be allowed in IIS?

Any help is highly appreciated

Thanks a lot

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes
Accepted answer

2 additional answers

Sort by: Most helpful
  1. Anonymous
    2024-11-26T12:21:19+00:00

    Hello Sabine Ludewig,

    Thank you for posting in Microsoft Community forum.

    From the description above, I understand your question is related to IIS.

    Since there are no engineers dedicated to IIS in this forum. in order to be able to get a quick and effective handling of your issue, I recommend that you repost your question in the Q&A forum, where there will be a dedicated engineer to give you a professional and effective reply.

    Here is the link for Q&A forum.
    Questions - Microsoft Q&A

    Click the "Ask a Question" button in the upper right corner to post your question and type "Internet Information Services" tag and select any tags related to your productions.

    I hope the information above is helpful.

    If you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    0 comments No comments
  2. Anonymous
    2024-11-26T13:07:04+00:00

    Hello Daisy

    my question is not particulary about IIS.

    It's about about which IIS features OCSP requires (.Net trust level, allowed file extensions).

    Thanks

    0 comments No comments