Configure deterministic "good" for the online responder (OCSP).

In the default configuration, the online responder returns the status "Good" for requested certificates that do not appear on one of the configured revocation lists.

This can be problematic because the online responder has no knowledge of certificates issued by the certification authorities. If an attacker succeeds in issuing a certificate using the private key of the certification authority without their knowledge, this would not be detected by the online responder, and would also be reported in the Audit log show up as "Good".

Continue reading „Deterministisches „Good“ für den Onlineresponder (OCSP) konfigurieren“

Details of the event with ID 5127 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5127 (0x1407)
Event log:Security
Event type:Information
Event text (English):The OCSP Revocation Provider successfully updated the revocation information. CA Configuration ID: %1 Base CRL Number: %2 Base CRL This Update: %3 Base CRL Hash: %4 Delta CRL Number: %5 Delta CRL Indicator: %6 Delta CRL This Update: %7 Delta CRL Hash: %8
Event text (German):The OCSP response service has successfully updated the revocation information. Certification authority configuration ID: %1 Base revocation list number: %2 Base revocation list, this update: %3 Base revocation list hash: %4 Delta revocation list number: %5 Delta revocation list display: %6 Delta revocation list, this update: %7 Delta revocation list hash: %8
Continue reading „Details zum Ereignis mit ID 5127 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5121 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5121 (0x1401)
Event log:Security
Event type:Information
Event text (English):OCSP Responder Service Stopped.
Event text (German):The OCSP response service has been terminated.
Continue reading „Details zum Ereignis mit ID 5121 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5122 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5122 (0x1402)
Event log:Security
Event type:Information
Event text (English):A Configuration entry changed in the OCSP Responder Service. CA Configuration ID: %1 New Value: %2
Event text (German):A configuration entry was changed in the OCSP response service. Certification authority configuration ID: %1 New value: %2
Continue reading „Details zum Ereignis mit ID 5122 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5123 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5123 (0x1403)
Event log:Security
Event type:Information
Event text (English):A configuration entry changed in the OCSP Responder Service. Property Name: %1 New Value: %2
Event text (German):A configuration entry has been changed in the OCSP response service. Property name: %1 New value: %2
Continue reading „Details zum Ereignis mit ID 5123 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5124 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5124 (0x1404)
Event log:Security
Event type:Information
Event text (English):A security setting was updated on OCSP Responder Service. New Value: %1
Event text (German):A security setting has been updated for the OCSP response service. New value: %1
Continue reading „Details zum Ereignis mit ID 5124 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5125 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5125 (0x1405)
Event log:Security
Event type:Information
Event text (English):A request was submitted to OCSP Responder Service.
Event text (German):A request is transmitted to the OCSP response service.
Continue reading „Details zum Ereignis mit ID 5125 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5126 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5126 (0x1406)
Event log:Security
Event type:Information
Event text (English):Signing Certificate was automatically updated by the OCSP Responder Service. CA Configuration ID: %1 New Signing Certificate Hash: %2
Event text (German):The signing certificate was automatically updated by the OCSP response service. Certification authority configuration ID: %1 New signature certificate hash: %2
Continue reading „Details zum Ereignis mit ID 5126 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5059 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5059 (0x13C3)
Event log:Security
Event type:Information
Event text (English):Key migration operation. Subject: Security ID: %1 Account Name: %2 Account Domain: %3 Logon ID: %4 Cryptographic Parameters: Provider Name: %5 Algorithm Name: %6 Key Name: %7 Key Type: %8 Additional Information: Operation: %9 Return Code:
Event text (German):Key migration process. Applicant: Security ID: %1 Account name: %2 Account domain: %3 Login ID: %4 Cryptographic parameters: Provider Name: %5 Algorithm Name: %6 Key Name: %7 Key Type: %8 Additional Information: Operation: %9 Return code:
Continue reading „Details zum Ereignis mit ID 5059 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 5120 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:5120 (0x1400)
Event log:Security
Event type:Information
Event text (English):OCSP Responder Service Started.
Event text (German):The OCSP response service has been started.
Continue reading „Details zum Ereignis mit ID 5120 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 4895 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:4895 (0x131F)
Event log:Security
Event type:Information
Event text (English):Certificate Services published the CA certificate to Active Directory Domain Services. Certificate Hash: %1 Valid From: %2 Valid To: %3
Event text (German):The certificate services have published the certification authority certificate in the Active Directory domain services. Certificate hash: %1 Valid from: %2 Valid until: %3
Continue reading „Details zum Ereignis mit ID 4895 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 4896 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:4896 (0x1320)
Event log:Security
Event type:Information
Event text (English):One or more rows have been deleted from the certificate database. Table ID: %1 Filter: %2 Rows Deleted: %3
Event text (German):At least one row was deleted from the certificate database. Table ID: %1 Filter: %2 Deleted rows: %3
Continue reading „Details zum Ereignis mit ID 4896 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 4897 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:4897 (0x1321)
Event log:Security
Event type:Information
Event text (English):Role separation enabled: %1
Event text (German):Role separation activated: %1
Continue reading „Details zum Ereignis mit ID 4897 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 4898 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:4898 (0x1322)
Event log:Security
Event type:Information
Event text (English):Certificate Services loaded a template. %1 v%2 (Schema V%3) %4 %5 Template Information: Template Content: %7 Security Descriptor: %8 Additional Information: Domain Controller: %6
Event text (German):Certificate Services have loaded a template. %1 v%2 (Scheme V%3) %4 %5 Template information: Template content: %7 Security description: %8 Additional information: Domain Controller: %6
Continue reading „Details zum Ereignis mit ID 4898 der Quelle Microsoft-Windows-Security-Auditing“

Details of the event with ID 4899 of the source Microsoft-Windows-Security-Auditing

Event Source:Microsoft Windows Security Auditing
Event ID:4899 (0x1323)
Event log:Security
Event type:Information
Event text (English):A Certificate Services template was updated. %1 v%2 (Schema V%3) %4 %5 Template Change Information: Old Template Content: %8 New Template Content: %7 Additional Information: Domain Controller: %6
Event text (German):The certificate service template has been updated. %1 v%2 (Scheme V%3) %4 %5 Template information: Template content: %7 Security description: %8 Additional information: Domain Controller: %6
Continue reading „Details zum Ereignis mit ID 4899 der Quelle Microsoft-Windows-Security-Auditing“
en_USEnglish