Windows 10: certutil check OCSP status using HTTP GET method.

Discus and support certutil check OCSP status using HTTP GET method. in Windows 10 Network and Sharing to solve the problem; I use certutil to check the Status of certificates, which have only OCSP URL but not CRL Distribution Point. In this case certutil performes a HTTP GET... Discussion in 'Windows 10 Network and Sharing' started by DoneYA, Jan 24, 2019.

  1. DoneYA Win User

    certutil check OCSP status using HTTP GET method.


    I use certutil to check the Status of certificates, which have only OCSP URL but not CRL Distribution Point. In this case certutil performes a HTTP GET request and not HTTP POST and encodes URL characters as / and \. This is Problem for some OCSP responders. Is it posible to configure certutil to use always the HTTP POST method by performing OCSP Request?

    :)
     
    DoneYA, Jan 24, 2019
    #1
  2. DoneYA Win User

    certutil check OCSP status using HTTP GET method.

    I use certutil to check the Status of certificates, which have only OCSP URL but not CRL Distribution Point. In this case certutil performes a HTTP GET request and not HTTP POST and encodes URL characters as / and \. This is Problem for some OCSP
    responders. Is it posible to configure certutil to use always the HTTP POST method by performing OCSP Request?
     
    DoneYA, Oct 10, 2019
    #2
  3. Amit_Sun Win User
    certutil check OCSP status using HTTP GET method.

    Hi,



    Thank you for writing to Microsoft Community Forums.



    I understand this is an important feature for you and you want this to work, you can go through this article

    Certutil
    and check if this is helpful to you. However, I suggest you to post your query on

    TechNet
    forums, where we have support professionals who are well equipped with the knowledge on this issue to assist you with your query.



    Regards,

    Amit Sunar

    Microsoft Community – Moderator
     
    Amit_Sun, Oct 10, 2019
    #3
  4. debbasu Win User

    certutil check OCSP status using HTTP GET method.

    OCSP Verification failed with error code

    Hi All,

    Can you please help us with following error while configuring OCSP while validating through below command. CDP and AIA is working but OCSP validation have issue. Though OCSP configuration showing no error.

    certutil -verify -urlfetch C:\Users\user\Desktop\test.cer



    ---------------- Certificate OCSP ----------------

    Failed "OCSP" Time: 0

    Error retrieving URL: Method not allowed (405). 0x80190195 (-2145844843 HTTP_E_STATUS_BAD_METHOD)


    http://crl2.domain.local/ocsp


    Also PKI view shows below error:


    certutil check OCSP status using HTTP GET method. fb02783f-36ad-41e8-a829-79476ca13f18?upload=true.jpg


    Please find the environment details as follows.

    Currently we have two enterprise PKI env.

    Old Env: Single Server served as Root CA and Issuing CA

    New Env: Two layer architecture: Offline Root CA and Enterprise Issuing CA
     
    debbasu, Oct 10, 2019
    #4
Thema:

certutil check OCSP status using HTTP GET method.

Loading...
  1. certutil check OCSP status using HTTP GET method. - Similar Threads - certutil check OCSP

  2. Printer keeps printing "GET /eSCL/Scanner status HTTP/1.1 Host: localhost".

    in Windows 10 Gaming
    Printer keeps printing "GET /eSCL/Scanner status HTTP/1.1 Host: localhost".: I have Windows 11 and some months ago bought a Epson WF-3820 printer/scanner without issues. Recently the printer keeps printing out "GET /eSCL/Scanner status HTTP/1.1 Host: localhost" seemingly receiving a signal from my desktop computer. I've checked all settings as...
  3. Hardware dashboard api http status code 403

    in Windows 10 Drivers and Hardware
    Hardware dashboard api http status code 403: Hello,We Use Hardware dashboard API to sign our driver. but recently the dashboard api return https status code 403, no other info. https://answers.microsoft.com/en-us/windows/forum/all/hardware-dashboard-api-http-status-code-403/08f547d2-169b-4462-9613-028e754d3abb
  4. Hardware dashboard api http status code 403

    in Windows 10 Gaming
    Hardware dashboard api http status code 403: Hello,We Use Hardware dashboard API to sign our driver. but recently the dashboard api return https status code 403, no other info. https://answers.microsoft.com/en-us/windows/forum/all/hardware-dashboard-api-http-status-code-403/08f547d2-169b-4462-9613-028e754d3abb
  5. Hardware dashboard api http status code 403

    in Windows 10 Software and Apps
    Hardware dashboard api http status code 403: Hello,We Use Hardware dashboard API to sign our driver. but recently the dashboard api return https status code 403, no other info. https://answers.microsoft.com/en-us/windows/forum/all/hardware-dashboard-api-http-status-code-403/08f547d2-169b-4462-9613-028e754d3abb
  6. CertUtil

    in Windows 10 Network and Sharing
    CertUtil: CertUtil CertUtil -dump https://answers.microsoft.com/en-us/windows/forum/all/%E8%BF%90%E8%A1%8Ccertutil%E6%98%AF%E5%81%9A/d3b803fa-d285-4cdf-bd54-5396e791c824
  7. CertUtil

    in Windows 10 Gaming
    CertUtil: CertUtil CertUtil -dump https://answers.microsoft.com/en-us/windows/forum/all/%E8%BF%90%E8%A1%8Ccertutil%E6%98%AF%E5%81%9A/d3b803fa-d285-4cdf-bd54-5396e791c824
  8. CertUtil

    in Windows 10 Software and Apps
    CertUtil: CertUtil CertUtil -dump https://answers.microsoft.com/en-us/windows/forum/all/%E8%BF%90%E8%A1%8Ccertutil%E6%98%AF%E5%81%9A/d3b803fa-d285-4cdf-bd54-5396e791c824
  9. Key Status Check

    in Windows 10 Gaming
    Key Status Check: HII wanted to know that, is any way to check Microsoft activation key will activate without any errors before activation on the PC. I use Microsoft PID Checker but it only shows its OEM or RETAIL. I wanted to check the status of the key, before the activation it will work...
  10. Key Status Check

    in Windows 10 Software and Apps
    Key Status Check: HII wanted to know that, is any way to check Microsoft activation key will activate without any errors before activation on the PC. I use Microsoft PID Checker but it only shows its OEM or RETAIL. I wanted to check the status of the key, before the activation it will work...

Users found this page by searching for:

  1. certutil Invalid signature OCSP Time: