: Revoking Certificates
Focus
Focus

Revoking Certificates

Table of Contents

Revoking Certificates

You can revoke certificates that should no longer be trusted, such as certificates that have been replaced, compromised, or are no longer needed.
Next-Gen Trust Security supports certificate revocation for the following certificate authorities:
  • AWS
  • Microsoft AD CS
  • Venafi Zero Touch PKI
  • DigiCert
  • DigiCert One
  • ACMEv2
  • EJBCA
  • GlobalSign MSSL
  • HID PKIaaS
  • Sectigo Certificate Manager
  • CyberArk Certificate Manager - Self-Hosted
  • Google Cloud Certificate Authority Service
  • GoDaddy
  • OpenSSL

Before You Begin

  • The certificate must be issued by a supported certificate authority.
  • The certificate must be present in the Certificate Inventory.

Revoke a Certificate

  1. Sign in to Next-Gen Trust Security.
  2. Click Inventory > Certificates.
  3. Locate the certificate you want to revoke and open its details.
  4. Click Revoke.
  5. If prompted, confirm the certificate authority account associated with the certificate.Only the issuing certificate authority can revoke the certificate.
  6. In Revocation reason, select the most appropriate reason.Revocation reasons are defined by RFC 5280 and include:
    • Superseded: The certificate has been replaced with a newer one.
    • Affiliation changed: The certificate owner’s relationship with the issuer has changed.
    • Cessation of operation: The service or system using the certificate is no longer in operation.
    • Key compromise: The private key is suspected or confirmed to be compromised.
    • Unspecified: No specific reason applies.
  7. Optional: Enter a comment to help identify the reason for the revocation later.
  8. Select the confirmation checkbox, then click Revoke.
The certificate is submitted for revocation with the issuing certificate authority.You can monitor the certificate’s revocation status from the Certificate Inventory.