Chapter 4. CA: Finding and Revoking Certificates
54
• Key compromised
• CA key compromised
• Affiliation changed
• Certificate superseded
• Cessation of operation
• Certificate is on hold
10. Enter any additional comment. The comment is included in the revocation request.
When the revocation request is submitted, it is automatically approved, and the certificate is revoked.
Revocation requests are viewed by listing requests with a status of
Completed
; see
Section 3.2,
“Listing Certificate Requests”
for more information.
4.4.2. Taking Ceritificates Off Hold
There can be instances when a certificate is inaccessible, and therefore should be treated as revoked,
but that certificate can be recovered. For example, a user may have a personal email certificate stored
on a flash drive which he accidentally leaves at home. The certificate is not compromised, but it should
be temporarily suspended.
That certificate can be temporarily revoked by putting it on hold (one of the options given when
revoking a certificate, as in
Section 4.4.1, “Revoking Certificates”
). At a later time — such as when the
forgotten flash drive is picked up — that certificate can be taken off hold and is again active.
1. Search for the on hold certificate, as in
Section 4.2, “Searching for Certificates (Advanced)”
. Scroll
to the
Revocation Information
section, and set the
Certificate is on hold
revocation reason as
the search criterion.
2. In the results list, click the
Off Hold
button by the certificate to take off hold.