Red Hat Certificate System (CS) provides methods for revoking certificates and for
producing lists of revoked certificates, called certificate revocation lists (CRLs). This
chapter describes the methods for revoking a certificate, describes CMC Revocation, and
provides details about CRLs and setting up CRLs.
This chapter contains the following sections:
•
•
•
•
•
Revocation
Certificates can be revoked by an end user (the original owner of the certificate), a server
administrator, or by a Certificate Manager agent. End users can revoke certificates by using
the Revocation form provided in the end-entity services interface. Agents can revoke
end-entity certificates by using the appropriate form in the Agent Services interface.
Certificate-based (SSL client authentication) or challenge-password-based authentication is
required in both cases.
•
Revocation
CMCRevocation
About CRLs
Setting Up the Issuance of CRLs
CRL Extension Reference
An end user can revoke only those certificates that contain the same subject name as in
the certificate presented for authentication; if using a challenge password, the user can
revoke only the certificate that is associated with that password. After successful
authentication, the server lists the certificates belonging to the end user. The end user
can then select the certificate to be revoked or can revoke all certificates in the list. The
Revocation and CRLs
Chapter 15
569
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?