Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Reverted from v. 5

...

This article describes how to revoke publish a Certificate Authority (CA) in Smart ID Certificate Manager (CM).This  

It may be a requirement that end-user certificates are not published in any directory until the issuing authority receives signed confirmation, from the end-user, that the certificate is in the user's possession. This task is done in Administrator's workbench (AWB).

...

.

Prerequisites

The following prerequisites apply:

...

Two administration officers must sign the request.

...

Both officers must have the following roles:

  • Use AWB

  • CA and Key tasks

...

CA certificate must have been

...

issued.

Step-by-step instruction

Publish CA

The On Hold reason can only be set on a CA with external key.

Not all reason codes are available for Signing Authorities, for example CaCompromise and AACompromise
  1. .

Signing completes the task and returns you to the AWB window.

Excerpt
nameRevoke Publish CA/SA
  1. In AWB, select the CA/SA to be revoked by highlighting itcertificate in the Authority Hierarchy in the explorer bar.

  2. Select Tools > Revoke Authority and select the revocation reason from the sub-menuPublish Authority and select the publication procedure you want to use.

  3. In the Signature dialog box, enter the PIN code. See Sign tasks in Certificate Manager for more information.

Revocation reasons

The available revocation reasons depends on the type of CA/SA and the current state of the CA/SA. The following table shows the available reasons and how a reason can be changed.

Current CA state and type

New state or reasons

Active CA

All reasons except On Hold

Active CA with external key

All reasons including On Hold

On Hold CA with external key

Reinstate or all reasons except On Hold

Revoked CA, Affiliation Changed, Superseded or Cessation of Operation

Key-, CA- or AA Compromise

Revoked CA, CA- or AA Compromise

Key Compromise

Revoked CA, Key Compromise

None

Related information