Certificate Revocation List
A periodic CRL timer runs, and each time it expires, it dumps the entire list of revocation information. The revocation check is performed when the CRL information is downloaded for the first time. When the subsequent timer expires, the revocation check is not performed unless the tunnels are forced to re-negotiate.
The
revocation-check crl
command is used to set crl as revocation type.
device(config-pki-trustpoint-trust1)# revocation-check crl
The
show pki crls
command displays the downloaded revocation information.
device# show pki crl < trustpoint_name >
The
clear pki crl
command is used to clear the downloaded revocation information.
device(config)# clear pki crl < trustpoint_name >
The
pki export crl command is used to export the CRL file of a given trustpoint. The following example
exports the CRL for the trustpoint trust 1 to the file crl_file.
device(config)# pki export crl trust1 url crl_file