crl-update-time (PKI)

Sets the frequency of CRL updates.
Syntax
crl-update-time { hours }
no crl-update-time
Parameters
hours
Defines the number of hours between CRL updates. The valid range is 1 through 1000 hours.
Modes

PKI trustpoint configuration sub-mode

Usage Guidelines

The no form of the command removes the configuration.

A periodic CRL timer runs and after every expiry, it dumps the entire list of revocation information. The revocation check is done when the CRL information is downloaded for the first time. When the subsequent timer expires, the revocation check is not done unless the tunnels are forced to re-negotiated.

Examples

The following example sets the CRL update frequency to one hour.

device(config)#pki trustpoint trust1
device(config-pki-trustpoint-trust1)# revocation-check crl
device(config-pki-trustpoint-trust1)# crl-query http://FI-PKI02.englab.ruckus.com/CertEnroll/englab-FI-PKI02-CA.crl
device(config-pki-trustpoint-trust1)# crl-update-time 1
History
Release version Command history
08.0.70 This command was introduced.