General · GraphQL enum

RevocationReason enum

Why a certificate was revoked, from the issuer's revocation entry.

The distinction is operational, not cosmetic: a key compromise means the private key is in someone else's hands and everything it signed is suspect, while a superseded certificate is ordinary rotation hygiene. Reference: RFC 5280 - CRLReason

Values

Enum Value Description

NOT_SPECIFIED

No reason applies: the certificate is not revoked, or the issuer used a reason code this build does not recognize. This is what every GOOD and UNKNOWN certificate reports.

UNSPECIFIED

No reason was given (CRLReason 0).

KEY_COMPROMISE

The private key is believed to be in someone else's hands (CRLReason 1). The most serious reason.

CA_COMPROMISE

The issuing authority's own key is believed compromised (CRLReason 2).

AFFILIATION_CHANGED

The subject's affiliation with the named organization changed (CRLReason 3).

SUPERSEDED

The certificate was replaced by a newer one (CRLReason 4). Ordinary rotation.

CESSATION_OF_OPERATION

The subject ceased the operation the certificate was issued for (CRLReason 5).

CERTIFICATE_HOLD

The certificate is temporarily suspended and may be reinstated (CRLReason 6).

REMOVE_FROM_CRL

The certificate is being removed from the revocation list (CRLReason 8).

PRIVILEGE_WITHDRAWN

A privilege the certificate asserted was withdrawn (CRLReason 9).

AA_COMPROMISE

An attribute authority is believed compromised (CRLReason 10).

Used by

  • TLS type: Reports on SSL (Secure Sockets Layer) and TLS (Transport Layer Security).

Example

Example

"NOT_SPECIFIED"