Mark an authentication certificate as Disallowed
To perform this action, you must have a user role that contains the Solution administrator permission.
You can mark an authentication certificate as Disallowed to immediately block it from being used during device authentication. This is useful when a certificate is compromised, retired, or should otherwise be prevented from authenticating without removing it from Device Trust Manager.
You can restore access at any time by changing the status back to Allowed.
See Mark authentication certificates as Disallowed for a detailed explanation.
In the Device Trust Manager menu, go to Authentication management > Authentication certificates.
From the Authentication certificate actions, select Add disallowed certificate.
Enter a Name for the authencation certificate that you will mark as Disallowed.
Choose an existing authentication policy or Create a new authentication policy.
Choose an Authentication CA from the dropdown list or Upload a certificate.
If you are chosing an existing an Authentication CA, define a Key/Value pair to to uniquely identify each certificate request. This helps distinguish output files when certificate values are not unique.
For example, an
organization nameand an associatedvalue.Select:
Add authentication certificate: Marks the selected authentication certificate as
Disallowed.Save and add another: Proceed to add more authentication certificates to the
Disallowedlist.
The authentication certificates that are marked as Disallowed appears in the Authentication certificates table, with the Accessibility state of the marked certificates as Disallowed.