Is there a dependency of the Network Devices Registration Service (NDES) with the NTAuthCertificates object?

The Network Device Registration Service (NDES) has two Registration Authority Certificates. With the enrollment agent certificate, certificate requests are signed and one can use the Configure NDES device template accordingly so that certificates are also only issued if the submitted certificate requests also have a corresponding signature..

Do you plan to use the Certification Authority connected to the NDES remove from the NTAuthCertificates objectThe question may arise as to whether mutual dependencies need to be taken into account here - after all, this requires Enroll on Behalf Of (EOBO) the presence of the certificate authority certificate in NTAuthCertificates.

Continue reading „Gibt es eine Abhängigkeit des Registrierungsdienstes für Netzwerkgeräte (NDES) mit dem NTAuthCertificates Objekt?“

Force domain controller (or other participants) to use an online responder (OCSP)

By default, Windows systems, even if an online responder (OCSP) is configured, will be sent to a certain number of OCSP requests fall back to a (if available) brevocation list, because this is usually more efficient in such a case. However, this behavior is not always desired.

For example, if one uses smart card logins, one might want to know if Logins were executed with unauthorized issued certificates. In conjunction with the deterministic good of the online responder you can thus create an (almost) seamless Audit trail create for all smartcard logins.

Continue reading „Domänencontroller (oder andere Teilnehmer) zwingen, einen Onlineresponder (OCSP) zu verwenden“

Details of the event with ID 5127 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5127 (0x1407)
Event log:Security
Event type:Information
Event text (English):The OCSP Revocation Provider successfully updated the revocation information. CA Configuration ID: %1 Base CRL Number: %2 Base CRL This Update: %3 Base CRL Hash: %4 Delta CRL Number: %5 Delta CRL Indicator: %6 Delta CRL This Update: %7 Delta CRL Hash: %8
Event text (German):The OCSP response service has successfully updated the revocation information. Certification authority configuration ID: %1 Base revocation list number: %2 Base revocation list, this update: %3 Base revocation list hash: %4 Delta revocation list number: %5 Delta revocation list display: %6 Delta revocation list, this update: %7 Delta revocation list hash: %8
Continue reading „Details zum Ereignis mit ID 5127 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5059 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5059 (0x13C3)
Event log:Security
Event type:Information
Event text (English):Key migration operation. Subject: Security ID: %1 Account Name: %2 Account Domain: %3 Logon ID: %4 Cryptographic Parameters: Provider Name: %5 Algorithm Name: %6 Key Name: %7 Key Type: %8 Additional Information: Operation: %9 Return Code: %10
Event text (German):Schlüsselmigrationsvorgang. Antragsteller: Sicherheits-ID: %1 Kontoname: %2 Kontodomäne: %3 Anmelde-ID: %4 Kryptografische Parameter: Anbietername: %5 Algorithmusname: %6 Schlüsselname: %7 Schlüsseltyp: %8 Zusätzliche Informationen: Vorgang: %9 Rückgabecode: %10
Continue reading „Details zum Ereignis mit ID 5059 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5120 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5120 (0x1400)
Event log:Security
Event type:Information
Event text (English):OCSP Responder Service Started.
Event text (German):The OCSP response service has been started.
Continue reading „Details zum Ereignis mit ID 5120 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5121 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5121 (0x1401)
Event log:Security
Event type:Information
Event text (English):OCSP Responder Service Stopped.
Event text (German):The OCSP response service has been terminated.
Continue reading „Details zum Ereignis mit ID 5121 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5122 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5122 (0x1402)
Event log:Security
Event type:Information
Event text (English):A Configuration entry changed in the OCSP Responder Service. CA Configuration ID: %1 New Value: %2
Event text (German):A configuration entry was changed in the OCSP response service. Certification authority configuration ID: %1 New value: %2
Continue reading „Details zum Ereignis mit ID 5122 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5123 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5123 (0x1403)
Event log:Security
Event type:Information
Event text (English):A configuration entry changed in the OCSP Responder Service. Property Name: %1 New Value: %2
Event text (German):A configuration entry has been changed in the OCSP response service. Property name: %1 New value: %2
Continue reading „Details zum Ereignis mit ID 5123 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5124 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5124 (0x1404)
Event log:Security
Event type:Information
Event text (English):A security setting was updated on OCSP Responder Service. New Value: %1
Event text (German):A security setting has been updated for the OCSP response service. New value: %1
Continue reading „Details zum Ereignis mit ID 5124 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5125 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5125 (0x1405)
Event log:Security
Event type:Information
Event text (English):A request was submitted to OCSP Responder Service.
Event text (German):A request is transmitted to the OCSP response service.
Continue reading „Details zum Ereignis mit ID 5125 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5126 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5126 (0x1406)
Event log:Security
Event type:Information
Event text (English):Signing Certificate was automatically updated by the OCSP Responder Service. CA Configuration ID: %1 New Signing Certificate Hash: %2
Event text (German):The signing certificate was automatically updated by the OCSP response service. Certification authority configuration ID: %1 New signature certificate hash: %2
Continue reading „Details zum Ereignis mit ID 5126 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 4895 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:4895 (0x131F)
Event log:Security
Event type:Information
Event text (English):Certificate Services published the CA certificate to Active Directory Domain Services. Certificate Hash: %1 Valid From: %2 Valid To: %3
Event text (German):The certificate services have published the certification authority certificate in the Active Directory domain services. Certificate hash: %1 Valid from: %2 Valid until: %3
Continue reading „Details zum Ereignis mit ID 4895 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 4896 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:4896 (0x1320)
Event log:Security
Event type:Information
Event text (English):One or more rows have been deleted from the certificate database. Table ID: %1 Filter: %2 Rows Deleted: %3
Event text (German):At least one row was deleted from the certificate database. Table ID: %1 Filter: %2 Deleted rows: %3
Continue reading „Details zum Ereignis mit ID 4896 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 4897 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:4897 (0x1321)
Event log:Security
Event type:Information
Event text (English):Role separation enabled: %1
Event text (German):Role separation activated: %1
Continue reading „Details zum Ereignis mit ID 4897 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 4898 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:4898 (0x1322)
Event log:Security
Event type:Information
Event text (English):Certificate Services loaded a template. %1 v%2 (Schema V%3) %4 %5 Template Information: Template Content: %7 Security Descriptor: %8 Additional Information: Domain Controller: %6
Event text (German):Certificate Services have loaded a template. %1 v%2 (Scheme V%3) %4 %5 Template information: Template content: %7 Security description: %8 Additional information: Domain Controller: %6
Continue reading „Details zum Ereignis mit ID 4898 der Quelle Microsoft-Windows-Security-Auditing“
en_USEnglish