Managing the Certificate Revocation ListChapter 4 Finding and Revoking Certificates 65Managing the Certificate Revocation ListBy revoking a certificate, you are notifying other users that the certificate is nolonger valid. You make this notification by publishing a list of the revokedcertificates, called the certificate revocation list (CRL), to an LDAP directory. This listis publicly available and ensures that revoked certificates are not misused.Viewing or Examining CRLsIn some cases, you may need to view or examine the CRL, for example, prior tomanually updating the directory with the latest CRL.Only a Certificate Manager agent can view the CRL.To view or display the CRL:1. Go to the Certificate Manager Agent Services page (see “Accessing AgentServices” on page 25). You must submit the proper client certificate to getaccess to this page.2. Click Display Certificate Revocation List to display the form for viewing theCRL.3. Select the CRL that you want to view. (If your administrator has createdmultiple issuing points, you will see them in the “Issuing point” drop-downlist. Otherwise, you’ll only see the master CRL.)CAUTION Whether you are revoking a single certificate or a list of certificates,be extremely careful that you have selected the correct one or thatthe list contains only the certificates you want to revoke. Once youconfirm a revocation operation, there is no way to undo it.NOTE Certificate Management System is currently the only Netscapeserver that can check the revocation status of the certificates that itissues. With Certificate Management System, therefore, you can usethe certificate revocation status to control access. On other Netscapeservers, you must use other forms of access control. For example,you can remove individual users from access groups to preventthem from accessing the server.