이 콘텐츠는 선택한 언어로 제공되지 않습니다.

Chapter 25. revoker (Sending Revocation Requests)


The revoker utility sends revocation requests to the CA agent interface to revoke certificates. To access the interface, revoker needs to have access to an agent certificate that is part of the subsystem group that is acceptable to the CA.
The revoker tool can do all of the following:
  • Specify which certificate or a list of certificates to revoke by listing the hexadecimal serial numbers.
  • Specify a revocation reason.
  • Specify an invalidity date.
  • Unrevoke a certificate that is currently on hold.

25.1. Syntax

The revoker utility has the following syntax:

revoker -s serialNumber -n rsa_nickname [[ -p password ] | [ -w passwordFile ]] [ -d dbdir ] [ -v ] [ -V ] [ -u ] [ -r reasoncode ] [ -i numberOfHours ] hostname [ :port ]

Expand
Option Description
s Gives the serial numbers in hexadecimal of the certificates to revoke. A hexadecimal serial number, for example, is like 0x31, or multiple serial numbers can be listed separated by commas, such as 0x44,0x64,0x22.
n Gives the agent certificate nickname.
p Gives the certificate database password. Not used if the -w option is used.
w Optional. Gives the path to the password file. Not used if the -p option is used.
d Optional. Gives the path to the security databases.
v Optional. Sets the operation in verbose mode.
V Optional. Gives the version of the revoker tool.
u Optional. Unrevokes a certificate, meaning that certificate status is changed from on hold to active.
r Gives the reason to revoke the certificate. The following are the possible reasons:
  • 0 - Unspecified (default).
  • 1 - The key was compromised.
  • 2 - The CA key was compromised.
  • 3 - The affiliation of the user has changed.
  • 4 - The certificate has been superseded.
  • 5 - Cessation of operation.
  • 6 - The certificate is on hold.
i Sets the invalidity date in hours from current time for when to revoke the certificate.
hostname Gives the hostname of the server to which to send the request. Depending on how DNS and the network are configured, this can be a machine name, fully-qualified domain name, or IPv4 or IPv6 address.
port Optional. Gives the agent's SSL port number of the server.
맨 위로 이동
Red Hat logoGithubredditYoutubeTwitter

자세한 정보

평가판, 구매 및 판매

커뮤니티

Red Hat 문서 정보

Red Hat을 사용하는 고객은 신뢰할 수 있는 콘텐츠가 포함된 제품과 서비스를 통해 혁신하고 목표를 달성할 수 있습니다. 최신 업데이트를 확인하세요.

보다 포괄적 수용을 위한 오픈 소스 용어 교체

Red Hat은 코드, 문서, 웹 속성에서 문제가 있는 언어를 교체하기 위해 최선을 다하고 있습니다. 자세한 내용은 다음을 참조하세요.Red Hat 블로그.

Red Hat 소개

Red Hat은 기업이 핵심 데이터 센터에서 네트워크 에지에 이르기까지 플랫폼과 환경 전반에서 더 쉽게 작업할 수 있도록 강화된 솔루션을 제공합니다.

Theme

© 2025 Red Hat