Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

This article describes how to revoke a Certificate Authority (CA) in Nexus Certificate Manager (CM).

This task is done in Administrator's workbench (AWB) in Certificate Manager (AWB).

A CA with an external issuer can be set as revoked with the Externally Revoked CA command from the Tools menu. This will only change the state of the CA in the database, the actual CRL is issued by the external issuer. However, a CA must be set as revoked to be able to remove its key.

Prerequisites

 Prerequisites

The following prerequisites apply:

  • Two administration officers must sign the request.
  • Both officers must have the following roles:
    • Use AWB
    • CA and Key tasks

A connection to the CM host must have been established. See Connect to a CM host.

Step-by-step instruction

 Revoke CA
  1. In AWB, select the CA to be revoked by highlighting it.
  2. Select Tools > Revoke CA and select the revocation reason from the sub-menu.
  3. In the Signature dialog box, enter the PIN code. See Sign tasks for more information.

Revocation reasons

The available revocation reasons depends on the type of CA and the current state of the CA. The following table shows the available reasons and how a reason can be changed.

Current CA state and typeNew state or reasons
Active CAAll reasons except On Hold
Active CA with external keyAll reasons including On Hold
On Hold CA with external keyReinstate or all reasons except On Hold
Revoked CA, Affiliation Changed, Superseded or Cessation of OperationKey-, CA- or AA Compromise
Revoked CA, CA- or AA CompromiseKey Compromise
Revoked CA, Key CompromiseNone

The On Hold reason can only be set on a CA with external key.

  • No labels