
ClearPass Guest 3.9 | Deployment Guide Onboard | 85
Once the certificate has been revoked, future checks of the certificate’s validity using OCSP or CRL will
indicate that the certificate is no longer valid.
Note: Due to the way in which certificate revocation lists work, a certificate cannot be un-revoked. A
new certificate must be issued if a certificate is revoked in error.
Note: Revoking a device’s certificate will also prevent the device from being re-provisioned. This is
necessary to prevent the user from simply re-provisioning and obtaining a new certificate. To re-
provision the device, the revoked certificate must be deleted.
Delete certificate – Removes the certificate from the list. This option is only available if the data
retention policy is configured to permit the certificate’s deletion. See “Configuring Data Retention Policy
for Certificates”.
The Delete Certificate form is displayed. Mark the Delete this client certificate check box to confirm
the certificate’s deletion, and then click the Delete Certificate button.
Working with Certificate Signing Requests
Certificate signing requests can be managed through the Certificate Management list view. This allows for
server certificates, subordinate certificate authorities, and other client certificates not associated with a
device to be issued by the Onboard certificate authority.
Click on a certificate request to select it. You can then select from one of these actions:
View request – Displays the properties of the certificate request. Click the Cancel button to close
the certificate request properties.
Export request – Displays the Export Certificate Request form.
Comentarios a estos manuales