Certificate Revocation List

A Certificate Revocation List (CRL) is a list of certificates signed by the CA that are prematurely invalid.

A periodic CRL timer runs, and each time it expires, it dumps the entire list of revocation information. The revocation check is performed when the CRL information is downloaded for the first time. When the subsequent timer expires, the revocation check is not performed unless the tunnels are forced to re-negotiate.

The revocation-check crl command is used to set crl as revocation type.

device(config-pki-trustpoint-trust1)# revocation-check crl

The show pki crls command displays the downloaded revocation information.

device# show pki crl < trustpoint_name >

The clear pki crl command is used to clear the downloaded revocation information.

device(config)# clear pki crl < trustpoint_name >

The pki export crl command is used to export the CRL file of a given trustpoint. The following example exports the CRL for the trustpoint trust 1 to the file crl_file.

device(config)# pki export crl trust1 url crl_file