Hi Experts
set up 3 CAs(not MS CA) , key pairs are generated on HSM.
followed instruction ,http://www.forum.persianadmins.ir/showthread.php?t=12375
The issue is not happened 100% but when reboot OCSP service then Revocation Configuration Status says “Bad Signing on Array Controller”..
to recover from this status, need to run “Assign a signing certificate” which I run during setup phase.
For trouble shooting,
first I doubt the HSM so enable HSM library logs but it did not include any error , finding 3 key pairs.
next, I checked event log of CAPI2 but it also did not report any error.
so only OCSP responder application says “Bad Signing on Array Controller”
As I mentioned I could recover by running “Assign a signing certificate” again but bit uncomfortable to understand the reason
could you advice why OCSP responder application says “Bad Signing on Array Controller” when reboot OCSP service?
Regards
Y