Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7811573
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 2, 20262026-06-02T04:12:53+00:00 2026-06-02T04:12:53+00:00

I installed the AD, AD CS and OCSP on the same machine in my

  • 0

I installed the AD, AD CS and OCSP on the same machine in my lab and configured. I then use C# to have a OCSP client so that it can send the revocation check request and parse the response for a particular certificate installed on local machine. The C# code was built by using the Bouncy Castle assembly (http://www.bouncycastle.org/csharp/)

The problem is that, if I issued a certificate and revoked it on AD CS, and published the CRL and Delta CRL, my OCSP client still said this certificate is good, until I clicked the Refresh Revocation Data in AD CS -> OCSP -> Array Configuration.

I had configured the provider of my revocation configuration in OCSP to my local CRL through LDAP://XXXX and

I also specified my revocation provider to refresh the CRLs per 5 mins.

Is there any way I can set my OCSP “real-time”, which means after I revoked a certificate, and then my OCSP client will know that it had been revoked. Alternatively, my OCSP can get the CRL automatically instead of clicking the Refresh Revocation Data manually.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-02T04:12:55+00:00Added an answer on June 2, 2026 at 4:12 am

    OK I finally got how to make it as real time as possible, even though not that “real time”. The OCSP service have its own cache, and it seems that the revocation status for a certificate will be cached until the CRL expired. In my lab my CRL validity period was 2 days this means even though I revoked a certificate and published the CRL and set the OCSP refresh it every 5 mins, the original status would be in OCSP cache until 2 days later. But if I clicked the Refresh Revocation Data the OCSP will clear all caches and restart the application pool.

    The solution is, first I need to enable the NONCE extension in the OCSP service. So that when I sent the OCSP request I can take some random information in the NONCE. And in the OCSP service if it found that the request has ONONCE information it will NOT use any cache. So my revocation data will be refreshed after the 5 mins.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I installed MVC 1.0. Where's the System.Web.MVC dll so that I can use reflector
I installed the exception notification plugin from http://github.com/rails/exception_notification/tree/master I can confirm that my ActionMailer
Installed rubyinstaller-1.8.7-p358.exe, then tried to install jammit , but the config.gem command isn't being
I installed the paperclip plugin and was able to use it locally. When I
I installed Msys Git and TortoiseGIT x64. Whenever I try to use the Get
I installed wxWidgets and then followed the instructions to make it with MSYS. After
I installed Google Chrome Portable on the user's desktop and have the default homepage
Installed Magento 1.6.2.0, and noticed that the links are like http://MYSEUPERSTORE.com/ index.php /customer/account/ but
I installed maven and configured based on their 5 minute tutorial Created a eclipse
Installed a captcha on my blog, been good up until now. There have recently

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.