Event Source: | Microsoft-Windows-OnlineResponder |
Event ID: | 26 (0x1A) |
Event log: | Application |
Event type: | Error |
Symbolic Name: | MSG_E_CACONFIG_SIGNINGCERT_EXPIRED |
Event text (English): | The signing certificate for Online Responder configuration %1 has expired. OCSP requests for this configuration will be rejected. |
Event text (German): | The signing certificate for the %1 online responder configuration has expired. The OCSP requests for this configuration are rejected. |
Parameter
The parameters contained in the event text are filled with the following fields:
- %1: CAConfigurationId (win:UnicodeString)
The Online Responder (Online Certificate Status Protocol, OCSP) is an alternative way of providing revocation status information for certificates. Entities that want to check the revocation status of a certificate do not have to download the complete list of all revoked certificates thanks to OCSP, but can make a specific request for the certificate in question to the online responder. For a more detailed description, see the article "Basics Online Responder (Online Certificate Status Protocol, OCSP)„.
Description
This event occurs when the signing certificate for a revocation configuration has expired. The online responder will thus no longer be able to process new revocation requests.
For the effects, see also article "Effects of the failure of the online responder (OCSP) on the verification of the revocation status of a certificate„.
Safety assessment
The security assessment is based on the three dimensions of confidentiality, integrity and availability.
Since the revocation configuration has failed, availability is acutely impaired and thus the event is to be rated as critical.
Related links:
- Overview of Windows events generated by the online responder (OCSP)
- Overview of the audit events generated by the online responder (OCSP)