How to fetch a CRL directly from KCA LDAP database
Originally Published: 2002-12-16
Article Number
Applies To
Issue
Resolution
1. To retrieve PEM formatted CRL, you can use the following:
ldap://<KCA-host-name>:<LDAP-port>/md5=<MD5-of-the-CA>?certificaterevocationlist?
2. To retrieve the CRL in binary(DER), the following would work (*** Only when local CRL publishing is enabled):
ldap://<KCA-host-name>:<LDAP-port>/<DN-of-the-CA-cert>?certificaterevocationlist?
For example:
ldap://host.name:389:/c=us,st=ca,l=westerville,o=acme,ou=security,cn=myca?certificaterevocationlist?
Related Articles
createChangeRequest Delete Account web serivce call not working in RSA Identity Management and Governance 6.9.1 43Number of Views SQL Exception in the RSA Identity Governance and Lifecycle UI while saving the workflow after rollback 85Number of Views Cisco Umbrella - SAML Relying Party Configuration - SecurID Access Implementation Guide 13Number of Views Cisco Umbrella - SAML SSO Agent Configuration - SecurID Access Implementation Guide 16Number of Views TalentLMS - SAML Relying Party Configuration -SecurID Access Implementation Guide 2Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?