569
Chapter 15
Revocation and CRLs
Red Hat Certificate System (CS) provides methods for revoking certificates and for
producing lists of revoked certificates, called certificate revocation lists (CRLs). This
chapter describes the methods for revoking a certificate, describes CMC Revocation, and
provides details about CRLs and setting up CRLs.
This chapter contains the following sections:
•
Revocation
•
CMCRevocation
•
About CRLs
•
Setting Up the Issuance of CRLs
•
CRL Extension Reference
Revocation
Certificates can be revoked by an end user (the original owner of the certificate), a server
administrator, or by a Certificate Manager agent. End users can revoke certificates by using
the Revocation form provided in the end-entity services interface. Agents can revoke
end-entity certificates by using the appropriate form in the Agent Services interface.
Certificate-based (SSL client authentication) or challenge-password-based authentication is
required in both cases.
•
An end user can revoke only those certificates that contain the same subject name as in
the certificate presented for authentication; if using a challenge password, the user can
revoke only the certificate that is associated with that password. After successful
authentication, the server lists the certificates belonging to the end user. The end user
can then select the certificate to be revoked or can revoke all certificates in the list. The
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...