Show Table of Contents
15.2. Testing CMC Revocation
Test that CMC revocation is working properly by doing the following:
- Create a CMC revocation request for an existing certificate. For example, if the directory containing the agent certificate is
~jsmith/.mozilla/firefox/, the nickname of the certificate isCertificateManagerAgentCert, and the serial number of the certificate is22, the command is as follows:CMCRevoke -d"~jsmith/.mozilla/firefox/" -n"Certificate Manager Agent Cert" -i"cn=agentAuthMgr" -s22 -m0 -c"test comment"
- Open the CA's end-entities page.
- Select the Revocation tab.
- Select the CMC Revoke link in the menu.
- Paste the output from the
CMCRevokeoperation into the text box. Remove the-----BEGIN NEW CERTIFICATE REQUEST-----and----END NEW CERTIFICATE REQUEST-----lines from the pasted content. - Click .
- The results page displays that certificate 22 has been revoked.

Where did the comment section go?
Red Hat's documentation publication system recently went through an upgrade to enable speedier, more mobile-friendly content. We decided to re-evaluate our commenting platform to ensure that it meets your expectations and serves as an optimal feedback mechanism. During this redesign, we invite your input on providing feedback on Red Hat documentation via the discussion platform.