Yes, Microsoft AD CS environments can use Online Responders for OCSP. As with any security-critical PKI component, however, the architecture and administrative separation of CAs, revocation services, and Active Directory must be carefully designed.
Potential risks can arise when CA, OCSP, CRL, and administrative systems share the same trust boundaries, privileged accounts, or infrastructure.
Security can be improved through measures such as:
Isolated environments: OCSP responders and revocation infrastructure can be separated from Certification Authorities and other critical systems.
Strong authentication and access control: Multi-factor authentication and role-based access control can reduce the risk of unauthorized access.
Regular security reviews: Audits and security assessments help identify and address potential weaknesses at an early stage.
By using appropriate PKI architecture and security best practices, companies can improve the resilience and security of their OCSP and revocation infrastructure.