Configuring CA to issue OCSP response signing certificates
This section describes how to configure the CA to support the Online Responder service.
To configure the CA to support the Online Responder service, configure the certificate templates and issuing properties for OCSP Response Signing Certificates.
Note
If you have installed the CA and OCSP on same machine then you need to complete this procedure on OCSPSERV to configure OCSP Response Signing Certificate.
To configure certificate templates using SafeNet KSP
-
Log on to OCSPCA as a domain administrator.
-
Select Search, enter MMC, and press Enter to open the console.
-
In the mmc console, select File and Add/Remove Snap-in….
-
In the Add or Remove Snap-Ins dialog box, select the Certificate Templates snap-in (under the Available snap-ins section).
-
Select Add and OK.
-
Under Console Root, expand the Certificate Templates snap-in. The middle section lists all of the available certificate templates that CA can issue.
-
Scroll down the list until you locate the OCSP Response Signing template. Right-click the template and select Properties. The Template properties dialog displays.
-
Select the General tab and the Publish Certificate in the Active Directory check box.
-
Set the Validity Period and Renewal period.
Note
For testing purpose, this guide assumes the Validity period and Renewal period for four hours and one hour for Auto Renewal.
-
Select the Security tab and Add.
The Select User, Computers, Service Accounts, or Groups dialog displays.
-
Enter the name of the machine which is hosting the Online Responder service. In this case, the machine name is OCSPSERV.
-
Select OK.
The system should not be able to locate the machine, instead another dialog displays.
-
Select Object Types, the Computers check box, and then OK.
-
Re-enter OCSPSERV in the Select User, Computers, Service Accounts, or Groups dialog and select OK. The machine hosting the Online Responder will be added to the Group and user names area under the Security tab.
-
Select on OCSPSERV in the Group and user names area.
-
Select the Read, Enroll, and Autoenroll check boxes.
-
Ensure that the Read, Write, Enroll and Autoenroll check boxes are selected for both Domain Admins and Enterprise Admins, and select Apply.
-
Select the Cryptography tab. Select the Requests must use one of the following providers radio button. The dialog below the radio button activates.
-
Select SafeNet Key Storage Provider.
-
Select Apply and OK.
To configure the CA to support the Online Responder service
-
Log on to OCSPCA as a domain administrator.
-
From the Start menu, select Administrative Tools and Certification Authority.
-
In the console tree (left-hand section), select the CA name.
-
Open the Action menu and select Properties.
-
Select the Security tab and Add.
The Select User, Computers, Service Accounts, or Groups dialog displays.
-
Enter the name of the machine which is hosting the Online Responder service. In this case, the machine name is OCSPSERV.
-
Select OK.
The system should not be able to locate the machine, instead another dialog displays.
-
Select Object Types, the Computers checkbox, and OK.
-
Re-enter OCSPSERV in the Select User, Computers, Service Accounts or Groups dialog and select OK.
The machine hosting the Online Responder will be added to the Group and user names area under the Security tab.
-
Select OCSPSERV in the Group and user names area.
-
In the Permissions area, select the Request Certificate check box.
-
Ensure that the Issue and Manage Certificates, Manage CA, and Request Certificates check boxes are selected for Domain Admins, Enterprise Admins, and Administrators.
-
Select Extensions > Authority Information Access (AIA).
-
Select Add. In the Add Location dialog type under Location.
For example, the address when using OCSPSERV would be http://OCSPSERV/ocsp.
-
Select OK.
-
On the Extensions tab
-
Ensure that the recently added URL is highlighted.
-
Ensure that the Include in the AIA extension of issued certificates and Include in the online certificate status protocol (OCSP) extension check boxes are selected.
-
-
Select Apply and Yes to restart the Active Directory Certificate Services.
-
When the services restarts, select OK.
-
In the console tree of the Certification Authority snap-in, right-click Certificate Templates, and then select New Certificate Templates to Issue.
-
In Enable Certificates Templates, select the OCSP Response Signing template, any other previously configured certificate templates, and then OK.
-
Open Certificate Templates in the Certification Authority and verify that the modified certificate templates are included in the list.