Add a certificate revocation list to a trusted CA object

Add a certificate revocation list (CRL) to a trusted certificate authority (CA) object. This step ensures that revoked certificates are recognized during certificate validation.

Add a CRL to a trusted CA object to ensure that Secure Firewall Management Center validates client certificates against a list of revoked certificates.

Note

Adding a CRL to an object has no effect when the object is used in your ISE/ISE-PIC integration configuration.

Before you begin

Ensure you have a DER or PEM-encoded CRL file available for upload.

Procedure


Step 1

Choose Objects.

Step 2

Expand the PKI node, and choose Trusted CAs.

Step 3

Click Edit (edit icon) next to a trusted CA object.

If View (View button) appears instead, the configuration belongs to an ancestor domain, or you do not have permission to modify the configuration.

Step 4

Click Add CRL and upload your DER or PEM-encoded CRL file.

Step 5

Click OK to save the changes.


The certificate revocation list is added to the trusted CA object, updating it with the new CRL information.

What to do next

  • If an active policy references your object, deploy configuration changes.