Checking the revocation status of certificates

Trust Protection Platform automatically checks the revocation status of all enabled certificates in the inventory on a scheduled basis. You can configure this schedule as frequently as every hour, or as infrequently as once a day. If a certificate is found to be revoked, a notification will be sent to the contacts for the certificate and the status of the certificate will be updated. This keeps system administrators up to date on the status of their certificates in case they were aware of the revocation and need to update the revoked certificate with a new one.

Trust Protection Platform also provides the option to check the revocation status of an individual certificate at any time. Manually checking revocation is useful when you want to confirm that a revoked certificate is actually on the currently published CRL or even suspect that a specific certificate has been revoked without the appropriate approvals.

NOTE  Manual checking of a certificate only checks the current version of the certificate. Trust Protection Platform checks any certificates found on the History tab of enabled certificates (that have not expired or been revoked) during the scheduled revocation check.

You can also view the revocation status of all certificates within a policy object from that object's View > Certificate tabs.

For information on viewing the revocation status of multiple certificates at the same time, see Viewing the revocation status of multiple certificates.