Certificate Manager supports certificate enrollment over Certificate Management over CMS (CMC) as well as Revocation Request Control, which is used to request a certificate to be revoked. The request must be signed by an authorized CM officer with the revocation role, and one certificate revocation is allowed per request. CMC is an Internet Standard published by the IETF, defining transport mechanisms for the Cryptographic Message Syntax (CMS). It is defined in RFC 5272, its transport mechanisms in RFC 5273.
Verification of certificate requests
Protocol Gateway provides additional security by the option to require the user to be a CM Officer. Every request is being verified by three stages:
checking the Digest Message
checking the content type
verifying the officer who signed the request
Supported content types in requests and responses
The standard configuration supports the following content types of a request message:
The CMC Status info controls returns information about the status of a client/server request/response.
The status contains a code representing the success or failure of a specific operation. The CMC service supports Revocation Request Control which is used to request a certificate to be revoked. The request must contain the standard revocation information and be signed by an authorized CM officer with the revocation role.
Only mandatory fields are taken into consideration (issuerName, serialNumber and reason) and optional fields (invalidityDate, sharedSecret and comment) are ignored.
Supported reason codes in CMC revocation
The following reason codes are allowed in CMC revocation: