You can ensure that only valid certificates are being used for federation-related PKI functions by using CRLs against which certificates can be checked.
For Federation Manager to use a CRL, you have to specify the CRL location.
To specify the location of a CRL
The list of configured CRL locations is displayed.
The Add Certificate Revocation List is displayed.
Note: You can click Help for a description of fields, controls, and their respective requirements.
The location has to be a file path for a file CRL. The syntax for the file path is file:/path/filename.
Examples
The path on Solaris must be all lowercase.
The CRL is now added to the key database.
| Copyright © 2010 CA. All rights reserved. | Email CA about this topic |