WAS v8.5 > Reference > Sets

Certificate revocation list page

Use this page to determine the location of the certificate revocation list (CRL) known to the application server. The Application Server checks the CRL to determine the validity of the client certificate. A certificate found in a certificate revocation list might not be expired, but is no longer trusted by the certificate authority (CA) that issued the certificate. The CA might add the certificate to the certificate revocation list if it believes the client authority is compromised.

View the dmgr console panel for the collection certificate store on the server level.

  1. Click Servers > Server Types > WebSphere application servers > server_name.

  2. Under Security, click JAX-WS and JAX-RPC security runtime.

    In a mixed node cell with a server using Websphere Application Server version 6.1 or earlier, click Web services: Default bindings for Web Services Security.

  3. Under Additional properties, click Collection certificate store.

  4. Click the name of a configured collection certificate store or create a new collection certificate store first.

  5. Under Additional properties, click Certificate revocation list > Newto specify the path to a new list or click the name of the certificate revocation list to modify its path.

View the dmgr console page for the collection certificate store on the application level.

  1. Click Applications > Application Types > WebSphere enterprise applications > application_name.

  2. Under Modules, click Manage modules > URI_name.

  3. Under Web Services Security Properties, we can access collection certificate stores for the following bindings:

    • For the Request generator, click Web services: Client security bindings. Under Request generator (sender) binding, click Edit custom > Collection certificate store.

    • For the Request consumer, click Web services: Server security bindings. Under Request consumer (receiver) binding, click Edit custom > Collection certificate store.

    • For the Response generator, click Web services: Server security bindings. Under Response generator (sender) binding, click Edit custom > Collection certificate store.

    • For the Response consumer, click Web services: Client security bindings. Under Response consumer (receiver) binding, click Edit custom > Collection certificate store.

  4. Click the name of a configured collection certificate store or create a new collection certificate store first.

  5. Under Additional properties, click Certificate revocation list > New to specify the path to a new list or click the name of the certificate revocation list to modify its path.

  6. Under Additional properties, we can access collection certificate stores for the following bindings:

  7. Under Additional properties, click Collection certificate store > certificate_store_name.

  8. Under Additional properties, click X.509 certificates.

  9. Click New and specify the path to the certificate revocation list.


Certificate revocation list path

Location where we can find the list of certificates that are not valid.


Related


Configure the collection certificate store for the generator binding on the application level


Reference:

Certificate revocation list configuration settings
Collection certificate store page
Collection certificate store configuration settings


+

Search Tips   |   Advanced Search