Revocation Monitoring

From the Revocation Monitoring page in the Keyfactor Command Management Portal, you can manage CRLClosed A Certificate Revocation List (CRL) is a list of digital certificates that have been revoked by the issuing Certificate Authority (CA) before their scheduled expiration date and should no longer be trusted. and OCSP endpoints used for revocation monitoring. This includes adding, editing, deleting, and testing endpoints, as well as monitoring endpointClosed An endpoint is a URL that enables the API to gain access to resources on a server. responsiveness and configuring email alert notifications.

CRL monitoring provides visibility into endpoint availability (for example, missing files or unreachable locations), upcoming expiration, and expired CRLs. Alert timing is based on the CRL expiration date (not the Next Publish date), allowing you to define what constitutes a stale CRL. When email notifications are triggered, corresponding events are also written to the Windows event log on the Keyfactor Command server (Windows installations only).

OCSP monitoring is limited to endpoint responsiveness. Expiration is not applicable.

Tip:  Where to find this in the Management Portal:
Alerts → Revocation Monitoring
Note:  Revocation monitoring supports delivering alerts using either the legacy alerting system or the newer workflowClosed A workflow is a series of steps necessary to complete a process. In Keyfactor Command, it refers to the workflow builder, which allows you to automate event-driven tasks such as when a certificate is requested, revoked or found in a certificate store. system. The workflow system offers more options for injecting actions in the process than the legacy alerting system. To configure an alert to use the workflow system for alerting, set Use Workflows On and create a workflow for the alert (see details below).

When the alerts are run using workflow, there are two Keyfactor Command service jobs that perform this function. The first, running as scheduled for the alerts (see the Monitoring Execution Schedule for each alert), gathers any expiring or unreachable revocation monitoring endpoints that meet the alert criteria. The second, running every 10 minutes, takes the collected revocation monitoring endpoints and generates workflow instances for each.

Tip:  Click the help icon () next to the Revocation Monitoring page title to open the Keyfactor Software & Documentation Portal to this section. You will receive a prompt indicating:

You are being redirected to an external website ‘software.keyfactor.com'. Would you like to proceed?

You can also find Help in the NavigatorClosed The Navigator is the Keyfactor Command left-hand (newer versions) or top (older versions) navigation menu. Certificate collections and reports can be configured to be added to the menu using user-defined Show in Navigator settings.. From here you can choose to open either the Keyfactor Software & Documentation Portal at the home page or the Keyfactor API Endpoint Utility.

Keyfactor provides two sets of documentation: the On-Premises Documentation Suite and the Managed Services Documentation Suite. Which documentation set is accessed is determined by the Application Settings: On-Prem Documentation setting (see Application Settings: Console Tab).