Revoked certificate reason code does not display
Originally Published: 2004-06-10
Last Modified: 2023-10-06
Article Number
Applies To
Microsoft Windows 2000 Server SP4
Issue
The CRL Reason Code which appears in the published CRL using MS Windows is not the reason code which appears in the certificate. Reason code: "privilegeWithdrawn" shows up as "Unknown CRL Reason(9)".
RFC:
***
5.3.1 Reason Code
The reasonCode is a non-critical CRL entry extension that identifies the reason for the certificate revocation. CRL issuers are strongly encouraged to include meaningful reason codes in CRL entries. However, the reason code CRL entry extension SHOULD be absent instead of using the unspecified (0) reasonCode value.
id-ce-cRLReason OBJECT IDENTIFIER ::= { id-ce 21 }
-- reasonCode ::= { CRLReason }
CRLReason ::= ENUMERATED {
unspecified (0),
keyCompromise (1),
cACompromise (2),
affiliationChanged (3),
superseded (4),
cessationOfOperation (5),
certificateHold (6),
removeFromCRL (8),
privilegeWithdrawn (9),
aACompromise (10) }
***
Cause
Resolution
Related Articles
How do you add reason codes to the Certificate Revocation List (CRL) list on KCA? 3Number of Views Cloud Administration Clear PIN for Hardware Token API 53Number of Views Access policy is not enforced for some users in RSA Cloud Authentication Service 94Number of Views Why am I getting a "Registration Unsuccessful" message when registering a FIDO security key? 52Number of Views My Page Enrollment Policy 365Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?