Certificate revocation lists (CRLs) makes known any certificate and key that either client or server users should no longer trust. If data in a certificate changes, for example, a user changes offices or leaves the organization before the certificate expires, the certificate is revoked, and its data appears in a CRL.
To Install a CRLTo obtain a CRL from a CA, perform the following steps:
Obtain the CA's URL for downloading CRLs.
Enter the URL in your browser to access the site.
Follow the CA's instructions for downloading the CRL to a local directory.
Go to the configuration page in administration console.
Click the Configuration> Configuration Name > Certificates > Certificate Authorities tab.
Click Install CRL button
Enter the full path name to the associated file or browse and select the file.
Click OK.
Click Deploy for changes to take effect.