Use this page to edit or delete a CRL issuer.
The following are the configuration options for a CRL Issuer:
- Name - The name given by the CA Issuer.
- Description - Enter a meaningful description for the CRL.
- CRL Distribution URL - Enter the URL that ACS should use to retrieve the CRL. If a CA certificate contains a “CRL distribution points” parameter, this field will be populated automatically. Otherwise, be sure you specify a URL for the CRL corresponding to the CA you selected from the Issuer’s Certificate list. You can specify a URL that uses HTTP, LDAP, or FTP. Alternatively, you can specify the URL for the file itself, however this is only necessary when the repository URL lists multiple files. An example of an HTTP URL is:
http://crl.verisign.com/pca1.1.1.crl.
An example of an LDAP URL is:
ldap://10.36.193.5:388/CN=development-CA,CN=acs-westcoast2,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=cisco,DC=com
objectclass=CertificateRevocationListNote: In LDAP, the default placement for the CRL is under objectclass=crlDistributionPoint. ACS adds the object class information to the URL. If the CRL is located elsewhere, you need to add the object class to the URL. For example, if the CRL is situated under
the URL should be:
ldap://10.36.193.5:388/CN=development-CA,CN=acs-westcoast2,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=cisco,DC=com
Retrieve CRL — Initially ACS attempts to download a CRL from the CA. The CRL folder and file are created in the installation directory after a CRL is successfully downloaded. The CRL issuer is not modifiable. The Next Update field in the CRL file contains a value for the Next Update.
Select the method that ACS should use for retrieving a CRL.
Note: In both modes, if retrieval
fails for some reason, a reattempt is tried every 10 minutes.
This entry lists the status and the date and time of the last
CRL retrieval or retrieval attempt.
When the Ignore Expiration Date is unchecked, ACS examines the expiration date of the CRL in the Next Update field in the CRL file and continues to use this CRL even though it has expired. If the expiry date passed, the CRL is not valid and all EAP-TLS authentications will be rejected.
When the Ignore Expiration Date is checked, ACS continues to use the expired CRL and permits or rejects EAP-TLS authentications according to the contents of the CRL.
CRL is in Use — When checked, the CRL is active and is used in the EAP-TLS authentication process.
The Submit button downloads and verifies the CRL with the public key of the issuer. If there are inconsistencies, CRL Issuer Configuration errors are generated.
The Delete button deletes the CRL for a particular issuer.If there are inconsistencies, CRL Issuer Delete errors are generated.
When submission succeeds, restart ACS to apply the new configuration.
Change the settings as needed. If you change the CA certificate selection or the CRL distribution URL, you will be prompted to confirm your choice when you click Submit.
Note: If CRL is in Use is not checked, ACS does not enforce certificate revocations for the CA associated with the CRL issuer.