Skip to content

CRL Download for an "Active CA" #133

Answered by primetomas
qa-denis-huber asked this question in Q&A
Discussion options

You must be logged in to vote

If you have a key pair, it is a CA, and not pointing to another CA. In that case you generated the CRL in EJBCA. The CRL is then in the database (directly when it is generated) and you don't need to download it from somewhere else. In this case the OCSP responder does not use or need a CRL, since all issued certificates from this CA are in the database.

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@qa-denis-huber
Comment options

@primetomas
Comment options

@qa-denis-huber
Comment options

Answer selected by qa-denis-huber
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants