Revoking certificates and publishing CRL
- Access the OpenXPKI server.
- From a web browser, typehttp://ipaddress/openxpki/.Log in asOperator. The default password isopenxpki.The Operator login has two preconfigured operator accounts,raopandraop2.
- ClickWorkflow Search>Search now.Click a certificate to revoke, and then click the certificate link.From the Action section, clickrevocation request.Type the appropriate values, and then clickContinue>Submit request.On the next page, approve the request. The certificate revocation is waiting for the next CRL publish.From the PKI Operation section, clickIssue a certificate revocation list (CRL).ClickEnforce creation of revocation lists>Continue.From the PKI Operation section, clickPublish CA/CRL.ClickWorkflow Search>Search now.Click the revoked certificate with acertificate_revocation_request_v2type.ClickForce wake up.In the new CRL, you can find the serial number and the revocation reason of the revoked certificate.