How to fetch a CRL directly from KCA LDAP database
Originally Published: 2002-12-16
Article Number
Applies To
Issue
Resolution
1. To retrieve PEM formatted CRL, you can use the following:
ldap://<KCA-host-name>:<LDAP-port>/md5=<MD5-of-the-CA>?certificaterevocationlist?
2. To retrieve the CRL in binary(DER), the following would work (*** Only when local CRL publishing is enabled):
ldap://<KCA-host-name>:<LDAP-port>/<DN-of-the-CA-cert>?certificaterevocationlist?
For example:
ldap://host.name:389:/c=us,st=ca,l=westerville,o=acme,ou=security,cn=myca?certificaterevocationlist?
Related Articles
SQL Exception in the RSA Identity Governance and Lifecycle UI while saving the workflow after rollback 85Number of Views Cisco Umbrella - SAML SSO Agent Configuration - SecurID Access Implementation Guide 16Number of Views Cisco Umbrella - SAML Relying Party Configuration - SecurID Access Implementation Guide 13Number of Views CreateChangeRequest webservice call with <AccountChange> does not fail on SoD Violations for RSA Via Lifecycle & Governance 71Number of Views TalentLMS - SAML Relying Party Configuration -SecurID Access Implementation Guide 2Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to download the RSA Authentication Manager Console Root Certificate in DER format Access Policies RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager Patch Updates
Don't see what you're looking for?