Skip to main content

Revocation & CRL/OCSP

Revoking a certificate in Sectigo Edge is immediate and permanent. Sectigo Edge then publishes the new status to relying parties, through a certificate revocation list (CRL) and through pre-produced OCSP responses. Revocation and publication are tracked separately: if publication is briefly unavailable, the certificate stays revoked and publication is retried until it succeeds.

Revoke a certificate​

Revoke certificate immediately dialog with an RFC 5280 reason selector, a Promote healthy standby first option and an audited incident context field
Revocation is a one-party safety action. It cannot be undone.
  1. Open ConsoleCertificates, find the certificate set, and select Revoke.
  2. Choose the RFC 5280 reason: Key compromise, Superseded, Cessation of operation, Affiliation changed, Privilege withdrawn, Certificate hold or Unspecified.
  3. If the set has a healthy standby, leave Promote healthy standby first selected. The service then keeps running on the standby while the compromised certificate is removed.
  4. In Audited incident context, enter the ticket, evidence or other context. It becomes part of the audit record.
  5. Select Revoke now.

You need revocation permission and fresh MFA. One person is enough: revocation removes trust, so it does not need a second approver. New issuance still needs both trust domains.

warning

Revocation cannot be undone, and Certificate hold is no exception: you cannot release a held certificate from the console. If you need the service back, issue a new certificate.

tip

Revocation still works while the issuance kill switch is active. Pausing issuance during an incident does not stop you from revoking.

What relying parties see​

Certificates issued through the built-in path carry a CRL distribution point of this form:

https://sharppki.com/pki/<tenant-id>/crl/<connector-id>.crl
  • It answers GET and HEAD without a sign-in, because clients must be able to check status before they trust a certificate.
  • It always serves the latest committed CRL, with content type application/pkix-crl.
  • Responses may be cached for at most one hour.
  • When fewer than five minutes remain before the CRL's nextUpdate, or storage is unavailable, the endpoint returns 503. It never serves a stale CRL.

Publication cadence​

EventCRLOCSP
First successful issuance for an authorityCRL generation 1 is created, even if empty, so certificates never point at an uninitialized endpoint.good responses are pre-produced for both hashes.
A certificate is revokedA new CRL generation is requested immediately.New revoked responses are published immediately.
Publication failsThe certificate stays revoked. Its publication status is pending. Retries start after 1 minute, then every 5 minutes.Same: the revoked state is kept, and publication is retried durably.
Routine refresh—Each accepted response is refreshed one hour before its nextUpdate.

Each CRL publication is checked independently before it goes live: signature, issuer, cRLSign key usage, freshness, every required serial, reason and time, and a strictly increasing CRL number. A refresh can never overwrite or renumber an earlier generation.

Monitor and refresh​

Revocation page with OCSP response counts, an OCSP response table by signing authority and CertID hash, and CRL cards per CA
Revocation shows OCSP health per certificate and CertID hash, and CRL generation and next update per CA.

ConsoleRevocation shows:

  • healthy OCSP responses, responses needing attention (pending or refresh due) and current revocation lists
  • for each OCSP response: signing authority, serial, generation, CertID hash, status and next update
  • for each CA: CRL number, number of revoked entries, generation, next update and status
StatusMeaning
healthyA verified, current artifact is published.
pendingPublication is waiting or being retried.
refresh due (OCSP)The response is near its refresh point.
expired (CRL)The latest CRL has expired. The public endpoint returns 503.
externalMicrosoft ADCS: the local CA has not yet produced an accepted artifact for the latest change. See below.

To force a new publication:

ActionWhereConfirmation
Publish new CRLThe CA's card under Certificate revocation listsType REFRESH CRL
Refresh OCSP (or Queue, for ADCS)The response's row in OCSP response serviceType REFRESH OCSP

Both need revocation permission and fresh MFA, which are checked again on submit.

Publish a new revocation list dialog showing signing authority, current generation, required revocations and public endpoint, with a REFRESH CRL confirmation field
Publishing a CRL. The signer must return a fresh CA-signed CRL that contains every known revocation.

Microsoft ADCS​

With Microsoft ADCS, your local CA stays the authority. A healthy Windows Mesh Node assigned to the ADCS integration publishes and retrieves the CA-signed CRL and gets OCSP responses from your configured Microsoft Online Responder. Sectigo Edge verifies these artifacts before it serves them. It never fabricates an ADCS CRL or OCSP response.

  • The status shows external until the node uploads an accepted artifact. It then becomes healthy.
  • Publish new CRL is disabled for ADCS authorities. The button shows Local CA managed.
  • Publication requests survive node, CA and network outages and are redelivered.
  • A successful ADCS CRL does not mean OCSP is working. They are tracked independently.

See Microsoft ADCS.

Verify revocation from a client​

workstation (bash)
curl -sI https://sharppki.com/pki/acme-corp/crl/ca_prod_issuing.crl
HTTP/2 200
content-type: application/pkix-crl
curl -s -o latest.crl https://sharppki.com/pki/acme-corp/crl/ca_prod_issuing.crl
openssl crl -inform DER -in latest.crl -noout -nextupdate -crlnumber
nextUpdate=Oct  2 14:00:00 2026 GMT
crlNumber=0x2A
openssl ocsp -issuer issuing-ca.pem -cert service.pem -no_nonce \
  -url https://sharppki.com/pki/acme-corp/ocsp/ca_prod_issuing
service.pem: revoked
  This Update: Oct  1 14:00:00 2026 GMT
  Next Update: Oct  2 14:00:00 2026 GMT
  Reason: keyCompromise
  Revocation Time: Oct  1 13:58:41 2026 GMT

Use -no_nonce. A request with a nonce is rejected by the cache profile.

Errors you may see​

CodeMeaningWhat to do
certificate_not_revocableOnly an issued certificate can be revoked. It may already be revoked.Refresh the certificate list.
invalid_revocation_reasonThe reason is not recognized.Choose one of the listed reasons.
revocation_comment_too_longThe incident context is too long.Shorten it, and link to your ticket instead.
crl_context_requiredThe CA has not completed an issuance yet, so there is no CRL to publish.Issue one certificate first.
crl_expired (503 at the public URL)The latest CRL is expired or too close to expiry.Select Publish new CRL. If it keeps failing, check the CA connection.
crl_partition_requiredThe CA has more than 50,000 active revocations.A partitioned CRL configuration is needed. Raise it with your Sectigo Edge platform contact before the CA reaches this limit.
remote_crl_publication_failed / remote_ocsp_publication_failedThe protected signing service rejected the publication.Retry. If it persists, check the CA connector under ConsoleCAs & signing.
crl_publication_raced / ocsp_publication_racedAnother publication changed the generation at the same moment.Retry. Generations are never overwritten.