CRL Profiles

To publish CRL for users/devices that do not have external (internet) access in SaaS deployment:

    • Edit the certificate issuance template to include a custom CRLDP with the LB URL.
    • The LB URL must act as a load balancing point for the number of CC URLs.

URL to be configured in templates: https://[LB Host]:[httpsport]/avxapi/download-crl/[CA_Name]/ crl.crl

LB to be balanced: https://[CC1 Host]:30020/avxapi/download-crl/[CA_Name]/crl.crl , https://[CC2 Host]:30020/avxapi/download-crl/[CA_Name]/crl.crl

To publish the OCSP URL for the users/devices that do not have access to the SaaS tenant:

Create a certificate issuance template for those endpoints to enroll certificates from, and include the custom OCSP URL as the LB URL.

The LB URL can be load balanced between cloud connectors.

URL to be configured in templates: https://[LB Host]:[httpsport]/ocsp

LB to be balanced: https://[CC1 Host]:30022/ocsp, https://[CC2 Host]:30022/ocsp