Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Certificate Revocation List (CRL) Commands

Prev Next

Apply

Syntax

./nnl-mgmt.sh crl apply -file <crl-file> [-cafile <cafile> -overwrite <yes|no> -tenantid <tenantid>]

Parameter

Description

file

Mandatory. File containing the CRL.

cafile

Optional. The .pem file that contains the CA Cert to verify the CRL.

overwrite

Conditional. If the CRL file exists, you must supply this parameter. The value can be one of:

  • Yes: Overwrites an existing CRL with the same name.

  • No: Does not overwrite an existing CRL with the same name.

tenantid

Optional. CRL is applied to the certs from the attest_cert_chains table that are associated with this tenant. Default value is default.

Description

During Android Key Attestation, the certificate chain in the extension data is stored in the Server database. Use this command to apply the Certificate Revocation List (CRL) file and mark the revoked certificates.

This command also verifies the CRL using the issuer CA Cert passed in as an argument for -cafile. If not specified or if CRL verification fails using the provided issuer CA certificate, the command looks up the issuer CA certificate in the database.

If there is any revocation when you run this command, the status of the certificates in the Server database is updated, and the applied CRL is archived at $NNL_HOME/bin/nnl-mgmt/data/archived/crls/.

This command fails if file exists and overwrite is No.

Example

./nnl-mgmt.sh crl apply -file example.crl.pem -cafile ca.cert.pem -tenantid default -overwrite YES