crl-query (PKI)

Sets the Certificate Revocation List (CRL) query URL.
Syntax
crl-query { url }
no crl-query
Command Default

No CRL URL is specified by default.

Parameters
url
URL of the CRL Distribution Point.
Modes

PKI trustpoint configuration sub-mode

Usage Guidelines

The no form of the command removes the URL configuration.

The CRL Distribution Point (CDP) is used to retrieve a CA’s latest CRL, usually an LDAP server or HTTP (web) server. The CDP is normally expressed as an ldap://host/dir or http://host/path URL.

Examples

The following example configures the HTTP address shown as the URL to be queried for the latest Certificate Revocation List.

device# configure terminal
device(config)# pki trustpoint trust1
device(config-pki-trustpoint-trust1)# revocation-check crl
device(config-pki-trustpoint-trust1)# crl-query http://FI-PKI02.englab.ruckus.com/CertEnroll/englab-FI-PKI02-CA.crl
History
Release version Command history
08.0.70 This command was introduced.