Certificate revocation lists in trusted CA objects
A certificate revocation list is a security file that
-
can be uploaded to a trusted CA object
-
enables control of encrypted traffic based on whether the issuing CA has revoked a certificate, and
-
supports files encoded in Distinguished Encoding Rules (DER) or Privacy-enhanced Electronic Mail (PEM) formats.
Certificate revocation list usage in trusted CA objects
You can upload CRLs to a trusted CA object. If you reference that trusted CA object in an SSL policy, you can control encrypted traffic based on whether the CA that issued the session encryption certificate subsequently revoked the certificate.
Supported file formats for CRLs include:
-
Distinguished Encoding Rules (DER)
-
Privacy-enhanced Electronic Mail (PEM)
After you add the CRL, you can view the list of revoked certificates. If you want to modify a CRL you have uploaded to an object, you must delete the object and recreate it.
You can upload only files that contain a proper CRL. There is no limit to the number of CRLs you can add to a trusted CA object. However, you must save the object each time you upload a CRL, before adding another CRL.
Note | Adding a CRL to an object has no effect when the object is used in your ISE/ISE-PIC integration configuration. |