Revoked certificate reason code does not display
Originally Published: 2004-06-10
Article Number
Applies To
Microsoft Windows 2000 Server SP4
Issue
The CRL Reason Code which appears in the published CRL using MS Windows is not the reason code which appears in the certificate. Reason code: "privilegeWithdrawn" shows up as "Unknown CRL Reason(9)".
RFC:
***
5.3.1 Reason Code
The reasonCode is a non-critical CRL entry extension that identifies the reason for the certificate revocation. CRL issuers are strongly encouraged to include meaningful reason codes in CRL entries. However, the reason code CRL entry extension SHOULD be absent instead of using the unspecified (0) reasonCode value.
id-ce-cRLReason OBJECT IDENTIFIER ::= { id-ce 21 }
-- reasonCode ::= { CRLReason }
CRLReason ::= ENUMERATED {
unspecified (0),
keyCompromise (1),
cACompromise (2),
affiliationChanged (3),
superseded (4),
cessationOfOperation (5),
certificateHold (6),
removeFromCRL (8),
privilegeWithdrawn (9),
aACompromise (10) }
***
Cause
Resolution
Related Articles
Does KCA publish reason codes for revoked certificates? 4Number of Views Authentication Manager 8.x Quick Setup Access Code Not Displayed After Appliance Deployment 543Number of Views Is it possible to use custom revoked / suspended certificate reasons in RSA Certificate Manager? 12Number of Views QR code not displaying in the RSA Authentication Manager Prime Self-Service Portal (SSP) 356Number of Views RSA Authentication Manager Displays Unwanted Certificate Signing Requests (CSRs) in the Operations Console Certificate Man… 2.65KNumber of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent for UNIX Platform Support Matrix Troubleshooting RSA MFA Agent for Microsoft Windows Unable to login to RSA Authentication Manager Security Console as super admin Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update
Don't see what you're looking for?