0

I need to figure out how certificate revocation works on IIS. Certificate we are working with contains both url to CRL and OCSP.

  1. As I understand by default IIS uses CRL to verify if certificate is revoked, is that right? if it's true - can I just enable OCSP without stapling?
  2. Can I configure IIS to use OCSP if we are unable to check revocation via CRL?
  3. How can configure this only for specific site?
Ash
  • 101

0 Answers0