Prepare Certificate Template for OCSP Signing

Firstly, it is necessary to prepare a template to enroll OCSP servers for a certificate which uses the Utimaco CryptoServer.

  1. Open the Certificate Authority Manager.

  2. Open the Certificate Templates Console by right-clicking on the folder Certificate Templates and Manage.

tmpm16eivrt.jpg

Manage Certificate Templates

  1. Locate the OCSP Response Signing Certificate, and click on Duplicate Template.

tmpcs2jfb2j.jpg

Duplicate a Certificate Template

  1. It is advisable to change this certificate template to reflect your requirements. The following steps are the minimum changes necessary.

    1. In the General tab, change the Template display name and the Template name.

tmp6y91ougm.png

General Tab of Properties of New Template

b. In the Cryptography tab, change the Provider Category to Key Storage Provider, and check only the Utimaco CryptoServer Key Storage Provider.

tmp18a785p6.png

Cryptography Tab of Properties of New Template

c. In the Security tab, add all OCSP servers that will be hosting the OCSP service. Grant the server read and enroll rights.

tmpju4267re.png

Security Tab of Properties of New Template

  1. After finishing the configuration of the certificate template, confirm with OK . Then activate the OCSP certificate template.

tmpa3o74ul8.jpg

Certificate Template to Issue

  1. Select the newly created certificate template and confirm with OK.

tmp0me0y3z8.jpg

Enable Certificate Templates