How to add CRLDistributionPoint extension to certificates with a custom URI
Originally Published: 2003-03-24
Last Modified: 2023-10-06
Article Number
Applies To
Issue
Resolution
If it is required to automatically populate the CRLDP extension with a custom URI (HTTP based non-KCA URL), say:
http://crl.xyz123.com/ca.crl
A solution is available given the following assumptions:
- Certificates are issued through KCA OneStep
- 'Local CRL Publishing' is not enabled
- An extension profile is being used with OneStep to issue certificates
Below are the steps to appropriately configure the extension profile in KCA to accomplish this:
1. Go to the KCA Admin Interface -> System Configuration workbench -> select Extension Profiles link -> select the extension profile being used with OneStep to issue certificates that need the custom CRLDP extension -> click the Edit button -> mark the CRLDP extension as Mandatory -> select the Edit button against CRL Distribution Points.
If the script for CRLDP extension has not been changed, it might look like the following (excluding the Start/End markers):
+++++++++++++++ Start of Script +++++++++++++++++
{
name : 'CRL Distribution Points',
type : 'mandatory',
autogenerate : false,
noncritical : {
def : false,
editable : false,
visible : true,
type : 'mandatory'
},
cRLDistPointsSyntax : {
def : 1,
min : 1,
max : 10,
visible : true,
editable : true,
type : 'mandatory',
elements : [
{
editable : true,
visible : true,
type : 'optional',
distributionPoint : {
def : 'fullName',
editable : true,
visible : true,
type : 'mandatory',
value : {
min : 1,
max : 10,
def : 1,
editable : true,
visible : true,
elements : [
{
def : 'rfc822Name',
editable : true,
visible : true,
type : 'mandatory',
value : {
def : 'Administrator@your-domain.com',
editable : true,
visible : true,
type : 'mandatory',
validator : 'extCheckGenName(this)'
}
}
]
}
}
},
{
editable : true,
visible : true,
type : 'optional',
distributionPoint : {
def : 'nameRelativeToCRLIssuer',
editable : true,
visible : true,
type : 'mandatory',
value : {
min : 1,
max : 10,
def : 1,
editable : true,
visible : true,
elements : [
{
oid : {
def : 'myOID',
editable : true,
visible : true,
type : 'mandatory'
},
type : {
def : 'myType',
editable : true,
visible : true,
type : 'mandatory'
},
value : {
def : 'MyValue',
editable : true,
visible : true,
type : 'mandatory'
}
}
]
}
}
}
]
}
}
+++++++++++++++ End of Script +++++++++++++++++
2. Remove the above text and replace with the following (excluding the Start/End markers). Remember to change the HTTP URL 'http://crl.xyz123.com/ca.crl' in the script below to the correct one.
+++++++++++++++ Start of Script +++++++++++++++++
{
name : 'CRL Distribution Points',
type : 'mandatory',
autogenerate : false,
critical : {
def : false,
editable : false,
visible : false,
type : 'mandatory'
},
cRLDistPointsSyntax : {
def : 1,
min : 1,
max : 10,
visible : false,
editable : false,
type : 'mandatory',
elements : [
{
editable : false,
visible : false,
type : 'mandatory',
distributionPoint : {
def : 'fullName',
editable : false,
visible : false,
type : 'mandatory',
value : {
min : 1,
max : 10,
def : 1,
editable : false,
visible : false,
elements : [
{
def : 'uRI',
editable : false,
visible : false,
type : 'mandatory',
value : {
def : 'http://crl.xyz123.com/ca.crl',
editable : false,
visible : false,
type : 'mandatory',
validator : 'extCheckGenName(this)'
}
}
]
}
}
}
]
}
}
+++++++++++++++ End of Script +++++++++++++++++
3. Click Next and click Save to update the extension profile. All certificates issued through OneStep that use the above configured extension profile will include the custom CRLDP extension from this point forward.
NOTE: If you are testing this functionality and issuing certificates through the KCA Admin Interface (not through OneStep), close all browser windows and open a new browser window to connect to the KCA Admin interface. When vetting a certificate request, the administrator will need to click through a few pages before a certificate is issued; however, there will be no need to enter any data for the CRLDP extension.
Related Articles
How to set the CRLdp certificate extension to point to specific Web server to retrieve the CRL 5Number of Views Intermittent high CPU usage effecting overall performance in RSA Identity Governance & Lifecycle 7.x when using Password M… 109Number of Views How to set up a CRL Distribution Point in a certificate during certificate manual approval 10Number of Views AEP Proxy Windows Event Viewer App log: submitRequestToCA returned 8c020009 26Number of Views Storing a certificate for smart card logon on an RSA SecurID SID800 token using RSA Authentication Client 3.6 182Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?