Validation Authority

AppViewX PKIaaS Native CA supports the following revocation mechanisms:
  • CRL (Certificate Revocation List): Generates and publishes lists of revoked certificates with CA-defined/custom CRL Distribution Points.
  • OCSP (Online Certificate Status Protocol): Offers real-time validation of certificate status through OCSP responses with CA-defined/custom OCSP URI.
    Note: CRLDP and OCSP are provided by default, with the corresponding URLs defined by the CA. Additionally, custom URLs can be configured within the templates to include them in the issued certificates.

Prerequisites

SaaS deployment
  • CRL routed via CC will work only with the latest version of CC. This is applicable only if you are routing CRL and OCSP via CC. If you have internet access to mothership, it is not required.
  • CC to be installed with respective auto-enrollment protocol to enable the ports based on the deployment plan:
    • 30020 HTTPS ACME (CRL)
    • 30022 HTTP SCEP (OCSP)