Why a certificate was revoked, from the issuer's revocation entry.
The distinction is operational, not cosmetic: a key compromise means the private key is in someone else's hands and everything it signed is suspect, while a superseded certificate is ordinary rotation hygiene. Reference: RFC 5280 - CRLReason
Values
| Enum Value | Description |
|---|---|
|
|
No reason applies: the certificate is not revoked, or the issuer used a reason code this build does not recognize. This is what every GOOD and UNKNOWN certificate reports. |
|
|
No reason was given (CRLReason 0). |
|
|
The private key is believed to be in someone else's hands (CRLReason 1). The most serious reason. |
|
|
The issuing authority's own key is believed compromised (CRLReason 2). |
|
|
The subject's affiliation with the named organization changed (CRLReason 3). |
|
|
The certificate was replaced by a newer one (CRLReason 4). Ordinary rotation. |
|
|
The subject ceased the operation the certificate was issued for (CRLReason 5). |
|
|
The certificate is temporarily suspended and may be reinstated (CRLReason 6). |
|
|
The certificate is being removed from the revocation list (CRLReason 8). |
|
|
A privilege the certificate asserted was withdrawn (CRLReason 9). |
|
|
An attribute authority is believed compromised (CRLReason 10). |
Used by
TLStype: Reports on SSL (Secure Sockets Layer) and TLS (Transport Layer Security).
Example
Example
"NOT_SPECIFIED"