Configuring the certificate revocation list

Certificate revocation lists allow WebSphere® Application Server to revoke a client certificate that is sent by the web browser when the key is compromised or when access permission to the key is revoked.

A certificate revocation list (CRL) is a time-stamped list of certificates that were revoked by a certificate authority (CA). A certificate that is found in a certificate revocation list might not be expired. However, the certificate is no longer trusted by the certificate authority (CA) that issued it. The CA might add the certificate to the certificate revocation list if it believes that the client authority is compromised. For more information about configuring certificate revocation lists, see the IBM® WebSphere Application Server Information Center help (V8.0, V8.5).