Could not retrieve an OCSP response.

Andreas 1,336 Reputation points
2023-02-02T08:54:37.2433333+00:00

Hi,

We have 1 MS 2022 CA server, and have noticed on our DC`s the following error message

EventID 36928

Source Schannel

Could not retrieve an OCSP response.

   The Failure Reason is: REASON_OCSP_RESPONSE_RETRIEVAL_ERROR
    The OCSP Url is: 
   The previous OCSP response contained the following times:
      ThisUpdate: ‎1601‎-‎01‎-‎01T00:00:00.000000000Z
      NextUpdate: ‎1601‎-‎01‎-‎01T00:00:00.000000000Z

The attached data contains the certificate.

User's image

We don't have a OCSP installed, so why does this error message ? And as I understand we do not need any OCSP either. We only publish internal machine certificates so the machines can connect to the Wifi.

Please advice.

Thanks for any reply

/R

Andy

Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade
Windows for business | Windows Server | User experience | Other

8 answers

Sort by: Newest
  1. Andreas 1,336 Reputation points
    2023-02-03T07:45:16.1066667+00:00

    Hi,

    Thanks for reply, but this is just telling me generally about issues related to OSCP, please be more specific to my question since I am not following you.

    1. We don't have a OCSP installed, so why does this error message ? And as I understand we do not need any OCSP either.

    /R

    Andy

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. Limitless Technology 45,246 Reputation points
    2023-02-02T17:20:00.03+00:00

    Hi. Thank you for your question and reaching out. I’d be more than happy to help you with your query.

    Generally, an OCSP response cannot be retrieved when:

    The certificate issuer is not responding to OCSP requests. This could be because the OCSP responder is either down or not configured properly to accept requests.

    The issuing certificate authority (CA) has revoked the certificate and the revocation is not yet propagated.

    The OCSP responder is not responding to the requests due to a network or server error.

    The certificate is self-signed, meaning that it is not signed by a trusted CA and therefore not verifiable.

    The issuing CA has not configured the OCSP responder correctly, or has not made the OCSP service available.

    If the reply was helpful, please don’t forget to upvote or accept as answer, thank you.

    Was this answer helpful?

    0 comments No comments

  3. Limitless Technology 45,246 Reputation points
    2023-02-02T17:19:43.1133333+00:00

    Hi. Thank you for your question and reaching out. I’d be more than happy to help you with your query.

    Generally, an OCSP response cannot be retrieved when:

    The certificate issuer is not responding to OCSP requests. This could be because the OCSP responder is either down or not configured properly to accept requests.

    The issuing certificate authority (CA) has revoked the certificate and the revocation is not yet propagated.

    The OCSP responder is not responding to the requests due to a network or server error.

    The certificate is self-signed, meaning that it is not signed by a trusted CA and therefore not verifiable.

    The issuing CA has not configured the OCSP responder correctly, or has not made the OCSP service available.

    If the reply was helpful, please don’t forget to upvote or accept as answer, thank you.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.