z/OS Cryptographic Services PKI Services Guide and Reference
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Steps for revoking or suspending a certificate

z/OS Cryptographic Services PKI Services Guide and Reference
SA23-2286-00

Revoking or suspending a certificate means that you cannot continue to use the certificate. You might want to permanently revoke your certificate if you suspect your private key has been compromised. You might want to suspend (temporarily revoke) your certificate if you want to discontinue using it for a period of time (known as the suspension grace period).

If you suspend your certificate, the PKI administrator can resume (reactivate) the certificate, or permanently revoke it, if the certificate has not yet expired and the grace period has not elapsed. If the grace period has elapsed, the certificate is permanently revoked the next time the certificate revocation lists (CRLs) are issued.

Perform the following steps to revoke or suspend a certificate:
  1. On the PKI Services home page (see Figure 1), click Renew or revoke certificate. This displays a popup window with a list of certificates, as in Figure 1.

    _______________________________________________________________

  2. The popup window might list more than one certificate. The certificates are listed by nickname in the order they are installed in the browser. You might not be able to identify the PKI Services certificate you want to revoke or suspend. Highlight the entry you think is the right one and click OK. If the certificate you selected is one that PKI Services issued and it is not expired or revoked, this displays the "Renew or revoke a browser certificate" Web page. (See Steps for renewing a certificate.)
    Note: If this is not the PKI Services certificate you want to revoke or suspend, you need to close your browser before again clicking Renew or revoke certificate as in Step 1.

    _______________________________________________________________

  3. Make sure the certificate you want is the one described at the top of the Web page. Click Revoke or Suspend. Note that when you revoke a certificate, you can click the drop-down list (of reasons) to select a reason if you wish.

    _______________________________________________________________

  4. This displays a Web page that says Request submitted successfully. You can click Home page to return to the PKI Services home page.

    _______________________________________________________________

When you are done: You will no longer be able to use the certificate. If you suspended the certificate, contact your PKI administrator when you wish to have it resumed.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014