Revoke an intermediate CA
To revoke an intermediate CA, you must have two users with any of the following roles:
CA Admin
CA Operations
PKI Operations
PKI Manager
In DigiCert ONE, in the Manager menu (top right), select CA.
From the main menu, select to Manage CAs > Intermediates.
Select the root ICA to be revoked.
On the right corner of the Details section, select More actions (three dots) > Revoke CA.
On the Revoke CA dialog box:
Select Approver for the revocation request.
Enter Revocation date.
Enter Reason for the revocation.
Note
Only specific certificate types may be revoked with the reason “6 Certificate hold". if not applicable this option will not appear.
Enter any relevant notes for the approver.
Select Request to revoke CA.
The approver will receive an email containing the link to either approve or reject the revocation request. When the approver selects the link, a new approval screen opens up where the approver rejects or approves the request.
If the approver approves the request:
The CA is revoked and disabled. This stops all application level functions from acting on the CA. OCSP gets updated immediately while CRL will be updated upon the next generation.
If the approver rejects the request:
The CA remains unchanged. You must begin the revocation process again, if required.
Note
Upon revocation approval for on-premises installations issuing ETSI Qualified certificates:
All child CAs and end-entities are revoked (Reason: 0, unspecified).
A final CRL is published with the next update field value of "99991231235959Z”.
The requested CA is revoked.
Unrevoke a CA
Only certificates with revoke reason "6 Certificate hold" may be unrevoked. The process is the same as revoking a CA.