Skip to main content

Revocation

The Revocation screen (page heading Revocation distribution) shows whether relying parties can check the status of your certificates. It covers two independent mechanisms: OCSP responses for individual certificates and certificate revocation lists (CRLs) per signing authority.

ConsoleRevocation

What it's for​

  • Confirm that every issued certificate has a current OCSP response.
  • Confirm that every signing authority has a current CRL.
  • Refresh OCSP responses or publish a new CRL on demand.

To revoke a certificate, use Certificates. Revocation then flows into the CRL and OCSP responses shown here.

What you see​

Revocation distribution screen with three summary counters, the OCSP response service table and the certificate revocation lists cards
Revocation distribution.

Summary counters​

CounterMeaning
healthy OCSP responsesResponses that are current.
responses needing attentionResponses that are pending or refresh due.
current revocation listsHealthy CRLs out of all CRLs, for example 3/3.

OCSP response service​

Responses come only from the configured CA provider: the protected signer for SCM and bring-your-own authorities, or the assigned Windows node's pinned Online Responder for Microsoft ADCS. Each certificate has two responses, one for a SHA-1 and one for a SHA-256 CertID, so that older and newer clients both work.

ColumnContent
Signing authorityThe CA connector name and ID.
CertificateSerial number and response generation.
CertIDSHA1 or SHA256.
StatusResponse health (see below).
Next updateWhen the response must be refreshed, for example in 6h. Shows Refresh due when overdue, Local responder for ADCS responses not yet received, or Pending.
ActionRefresh, or Queue for ADCS.

The table loads 100 responses at a time. Select Load more responses to see more. If no certificate has been issued yet, it shows No issued certificate status records yet.

OCSP statusMeaning
healthyA current, verified response is published.
pendingNo response has been published yet.
refresh dueThe response is close to or past its next update and should be refreshed.
externalAn ADCS response that is waiting for the Windows node's Online Responder.

Certificate revocation lists​

One card per signing authority:

  • CRL n · k revoked, or Awaiting first publication.
  • Status: healthy, pending, expired or external.
  • Generation and Next update.
  • Publish new CRL, or Local CA managed (disabled) when your local CA publishes the CRL.

Publish a new CRL​

Publish a new revocation list dialog with signing authority, current generation, required revocations, public endpoint and a REFRESH CRL confirmation box
Publishing a new CRL.
  1. Select Publish new CRL on the signing authority's card (or Refresh CRL on CAs & signing).
  2. Review the details: Signing authority, Current generation, Required revocations and Public endpoint.
  3. Type REFRESH CRL exactly.
  4. Select Verify and publish.

The console confirms: CRL generation N published and independently verified.

The protected signer must return a fresh CA-signed CRL that contains every known revocation. Sectigo Edge checks the issuer, signature, entries, reasons, freshness and that the generation only ever increases before publishing it.

The Public endpoint has the form /pki/<tenant-id>/crl/<connector-id>.crl. Relying parties can fetch it without signing in.

Refresh OCSP responses​

Refresh certificate status responses dialog with signing authority, certificate serial, current status, public endpoint and a REFRESH OCSP confirmation box
Refreshing OCSP responses for one certificate.
  1. Find the certificate in the OCSP table and select Refresh (or Queue for ADCS).
  2. Review the Signing authority, Certificate serial, Current status (good or revoked) and Public endpoint.
  3. Type REFRESH OCSP exactly.
  4. Select Verify and publish both (or Verify and queue for ADCS).

Both the SHA-1 and SHA-256 responses are refreshed together. The console confirms one of:

  • SHA-1 and SHA-256 OCSP responses published for serial (serial number).
  • SHA-1 and SHA-256 Online Responder work queued for serial (serial number). The assigned Windows node will publish after independent verification. (ADCS)

The Public endpoint has the form /pki/<tenant-id>/ocsp/<connector-id>.

Permissions​

ActionRoles
View revocation statusEvery role
Publish a CRL, refresh OCSPPKI Operator, Tenant Admin. Requires MFA within the last ten minutes; the control plane checks this again when you submit.

See Revocation, CRL & OCSP for operating guidance.

Troubleshooting​

SymptomCause and fix
Verify and publish is greyed outThe confirmation text does not exactly match REFRESH CRL (or REFRESH OCSP). It is case-sensitive.
A CRL shows Awaiting first publicationNo CRL has been published for this authority yet. The first successful issuance creates generation 1; you can also publish one manually.
A CRL is pending after a revocationThe revocation succeeded but publication has not completed yet. It is retried automatically; you can also publish manually.
A CRL shows expiredThe CRL passed its next update. Publish a new CRL. Relying parties may reject certificates until you do.
OCSP responses show refresh dueSelect Refresh for each affected certificate.
Publishing fails with an MFA messageYour MFA is older than ten minutes. Sign in again.