Fortinet black logo

CLI reference

config system certificate crl

config system certificate crl

Use this command to import certificate revocation lists.

To ensure that FortiNDR validates only certificates that have not been revoked, periodically upload a current certificate revocation list from certificate authorities (CA) or use the online certificate status protocol (OCSP) to query the certificate status.

Syntax

config system certificate crl
    edit <name_str>
        set crl <cert_str>
    end

Variable

Description

Default

<name_str>

The name of this certificate revocation list.

crl <cert_str>

Enter or paste the certificate in PEM format to import it.

config system certificate crl

Use this command to import certificate revocation lists.

To ensure that FortiNDR validates only certificates that have not been revoked, periodically upload a current certificate revocation list from certificate authorities (CA) or use the online certificate status protocol (OCSP) to query the certificate status.

Syntax

config system certificate crl
    edit <name_str>
        set crl <cert_str>
    end

Variable

Description

Default

<name_str>

The name of this certificate revocation list.

crl <cert_str>

Enter or paste the certificate in PEM format to import it.