Refreshing a CRL file using the configuration menu

Prev Next

Use the menu options in this section to refresh a local Certificate Revocation List (CRL) file by downloading a new file from a specified remote location so that the NDR appliance can validate certificate revocation. Only one CRL file can be present on the system. When you download a new CRL file, the existing CRL file is automatically deleted.

Note

You must specify the URL of the direct path to the certificate file.

To refresh a local CRL file:

  1. Log in to the NDR as npadmin using the NDR IP address or FQDN. For example:

    $ ssh npadmin@10.1.0.1

    or

    $ ssh npadmin@exampleFQDN

  2. Enter privileged mode:

    npadmin@ia> enable

  3. Enter the npadmin password. The password can be 5 to 24 characters long.

    [sudo] password for npadmin: <password>

  4. Enter configuration mode:

    npadmin@ia# configure system

  5. Enter configuration CAC menu.

    npadmin@ia(config)# authentication

  6. In the CAC/PIV configuration menu, select 2 to configure the current authentication method.

  7. In the PKI Configuration menu, select 3 to enter the CRL Configuration menu. The following appears:

    CRL_Refresh.JPG
  8. Select 2 to configure the CRL retrieval interval.

  9. Select Q to save your changes and exit the menu