Certificate Revocation Lists
The KMES Series 3 supports the management and export of Certificate Revocation Lists (CRLs). Use these lists to manage single or mass certificates that must be revoked for various reasons, including those defined by third-party Certificate Authorities (CAs).Create CRLs
Perform the following steps to create a CRL:Log in to the KMES Series 3 application interface with an identity assigned the required permissions.
Export CRLs
Perform the following steps to export a CRL:Log in to the KMES Series 3 application interface with an identity assigned the required permissions.
Online Certificate Status Protocol (OCSP)
Online Certificate Status Protocol (OCSP) is an internet protocol for obtaining the revocation status of an X.509 digital certificate. It serves as an alternative to CRLs, primarily to address performance issues. In a PKI environment, it’s essential to determine whether a particular digital certificate is still valid or has been revoked due to reasons such as a compromised private key. CRLs provide this information, but as the list grows, it becomes increasingly inefficient to download and parse. OCSP addresses this by enabling a client to query the certificate status in real-time directly from a server maintained by the Certificate Authority (CA). The OCSP server returns a response indicating whether the certificate is still valid, has been revoked, or is unknown to the responder. This protocol enables applications to obtain timely information regarding the revocation status of certificates, improving the overall performance and scalability of certificate validation processes.Configure OCSP server
To configure OCSP on the KMES, perform the following steps:Set the following options:
| Option | Required configuration |
|---|---|
| Request Signature | Unchecked |
| Responding | Use issuer as responder |
| Responder ID | Key |
| Response Signature | Checked |
| Signing hash algorithm | SHA-1 |
| Included certificates | Signer Certificate |
| None required | Unchecked |

