windows server 2008 Microsoft AD CS

mary Anderson 1 Reputation point
2022-01-29T06:48:25.243+00:00

Hi everybody
Recently we are using Microsoft ADCS on windows server 2008 in our organization. we have an OSCP server beside our enterprise CA server. We have just noticed that the OCSP is CRL based in Microsoft CA and so as OCSP gets access to the CRL periodically sometimes OCSP returns "good" for revoked certificates because they are revoked between the two points of time that OCSP gets access to the CRL. It seems that there is a fix or update to solve this issue but I can not find the download link. can anyone help me. By the way, we can not change the version of our OS.

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,728 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vadims Podāns 8,941 Reputation points MVP
    2022-01-29T14:32:00.41+00:00

    There is no update for this behavior. The behavior is a fundamental property of CRL-based OCSP server. In order to reduce the load, OCSP caches the referenced CRL for a period specified in CRL (Next Update) and revocation is not detected immediately. In revocation configuration provider settings you can specify how often OCSP should check for CRL updates:
    169557-image.png

    do not set too small value, because OCSP can be overloaded with CRL download and update operations.

    we can not change the version of our OS

    interesting, why?

    0 comments No comments