revocation-check (PKI)

Specifies the method to be used for certificate revocation checks.
Syntax
revocation-check { crl | ocsp | none }
no revocation-chec k { crl | ocsp | none }
Command Default

revocation-check none

Parameters
crl
Sets the revocation check method to Certificate Revocation List (CRL).
ocsp
Sets the revocation check method to Online Certificate Status Protocol (OCSP).
none
Designates that no revocation check is to be done. This is the default.
Modes

PKI trustpoint configuration sub-mode

Usage Guidelines

The no form of the command removes the configuration.

Examples

The following example sets the revocation check method for trustpoint abcd to Online Certificate Status Protocol (OCSP).

device# configure terminal
device(config)# pki trustpoint abcd
device(config-pki-trustpoint-abcd)# ocsp http post
device(config-pki-trustpoint-abcd)# revocation-check ocsp
device(config-pki-trustpoint-abcd)# ocsp-url http://10.21.40.39:2560
device(config-pki-trustpoint-abcd)# fingerprint 3C:EA:EC:E6:F1:DD:3B:86:65:DE:58:F4:A2:75:D8:63:6D:23:68:40
device(config-pki-trustpoint-abcd)# exit
History
Release version Command history
08.0.70 This command was introduced.