Prepare certificate template for OCSP Signing

First, it is necessary to prepare a template to enroll OCSP servers for a certificate which uses the Utimaco CryptoServer.

  1. Open the command prompt and run the certtmpl.msc command

  2. Right-click the OCSP Response Signing template and click Duplicate Template

  3. Select appropriate windows version under Certificate Authority and Certificate Recipient drop-down box under Compatibility Settings

  4. Click OK

image-20251110-110116.png

Figure 110: Compatibility Tab window

  1. In the Resulting Changes menu click OK

  2. Go to the General tab and enter a name for the template

  3. Select the Subject Name tab

image-20251110-110136.png

Figure 111: Subject Name Tab window

  1. Uncheck the Include e-mail name in subject name check box

  2. Uncheck the E-mail name check box

  3. In the Request Handling tab, select the Purpose as Signature from the drop-down list.

    Select Authorize additional service accounts to access the private key checkbox

image-20251110-110206.png

Figure 112: Request Handling window

If you are using Smartcard Authentication, the prompt will go on the PIN Pad device to insert Smartcard and enter the pin. Then press OK button on the PIN Pad.

  1. Go to Cryptography tab, select Key Storage provide in the Provider category then select Algorithm name then Key Size. Check on the radio button for Request must use one of the following providers then select radio button for Utimaco CryptoServer Key storage provider and select the appropriate Hash Value

image-20251110-110246.png

Figure 113: Cryptography Tab window

  1. Go to Security Tab. Add the Computer Account and give Read, Write and Enroll permissions. Ensure Domain Admins and Enterprise Admins are having Enroll Permissions

  2. Click Apply and then Click OK

  3. Open the command prompt and run the certsrv.msc command

image-20251110-110307.png

Figure 114: Certificate Authority window

  1. Right-click the Certificate Templates node

  2. Select New then select Certificate Template to Issue

  3. Select new template for OCSP Response Signing, click OK

image-20251110-110406.png

Figure 115: Certificate Authority window