Hi All,
Firstly, yes, I know, this should have been installed before I issued my
first certificate
I have a standard three tier hierarchy, RootCa [offline], PolicyCA
[offline], IssuingCA [online]. Having issued 107 certificates to date, I'm
now going to introduce the OCSP service. Has anyone any gotcha's or things
to be wary of having gone about such a reverse procedure in the past? From
what i read...
* I install the OCSP service on my IssuingCA
* Then hit my RootCA, and add the new http URL
* Issue new RootCA cert
* Issue new PolicyCA cert
* Issue new IssuingCA cert
Can anyone offer some basic steps as to how best to go about this?
Many thanks in advance,
Orb.