Prepare Certificate Template for OCSP Signing

First, it is necessary to prepare a template to enroll OCSP servers for a certificate which uses the Utimaco CryptoServer.

  1. Open the command prompt and run the certtmpl.msc command.

  2. Right-click the OCSP Response Signing template and click Duplicate Template.

  3. Selectthe appropriate Windows version under Certificate Authority and Certificate Recipient drop-down box under Compatibility Settings.

  4. Click OK.

image-20250805-111305.png


"Compatibility Tab" Window

  1. In the Resulting Changes menu, click OK.

  2. Go to the General tab and enter a name for the template.

  3. Select the Subject Name tab.

image-20250805-111329.png


"Subject Name Tab" Window

  1. Uncheck the Include e-mail name in subject name checkbox.

  2. Uncheck the E-mail name checkbox.

  3. In the Request Handling tab, select the Purpose as Signature from the drop-down list. Select Authorize additional service accounts to access the private key checkbox.

image-20250805-111413.png


"Request Handling" Window

If you are using smartcard authentication, the prompt will appear on the PIN Pad device to insert the smartcard and enter the PIN. Then, press the OK button on the PIN Pad.

  1. Go to the Cryptography tab, select Key Storage provider in the Provider category, then select Algorithm name, then Key Size. Check the radio button for Request must use one of the following providers, then selectthe radio button for Utimaco CryptoServer Key storage provider, and select the appropriate Hash Value.

image-20250805-111502.png


"Cryptography Tab" Window

  1. Go to the Security Tab. Add the Computer Account and give Read, Write and Enroll permissions. Ensure Domain Admins and Enterprise Admins have Enroll Permissions.

  2. Click Apply and then click OK.

  3. Open the command prompt and run the certsrv.msc command.

image-20250805-111557.png


"Certificate Authority" Window

  1. Right-click the Certificate Templates node.

  2. Select New, then select Certificate Template to Issue.

  3. Select a new template for OCSP Response Signing, and click OK.

image-20250805-111637.png


"Certificate Authority" Window