Apply
Syntax
./nnl-mgmt.sh crl apply -file <crl-file> [-cafile <cafile> -overwrite <yes|no> -tenantid <tenantid>]Parameter | Description |
|---|---|
file | Mandatory. File containing the CRL. |
cafile | Optional. The .pem file that contains the CA Cert to verify the CRL. |
overwrite | Conditional. If the CRL file exists, you must supply this parameter. The value can be one of:
|
tenantid | Optional. CRL is applied to the certs from the attest_cert_chains table that are associated with this tenant. Default value is default. |
Description
During Android Key Attestation, the certificate chain in the extension data is stored in the Server database. Use this command to apply the Certificate Revocation List (CRL) file and mark the revoked certificates.
This command also verifies the CRL using the issuer CA Cert passed in as an argument for -cafile. If not specified or if CRL verification fails using the provided issuer CA certificate, the command looks up the issuer CA certificate in the database.
If there is any revocation when you run this command, the status of the certificates in the Server database is updated, and the applied CRL is archived at $NNL_HOME/bin/nnl-mgmt/data/archived/crls/.
This command fails if file exists and overwrite is No.
Example
./nnl-mgmt.sh crl apply -file example.crl.pem -cafile ca.cert.pem -tenantid default -overwrite YES