# Azion CLI crl

The Azion CLI `crl` commands create, list, describe, update, and delete certificate revocation lists (CRLs) in [Certificate Manager](/en/documentation/platform/workloads/certificate-manager/certificates/#certificate-revocation-lists). A CRL is a list of revoked certificates that a Certificate Authority (CA) issues, and the CLI uploads it from a file in PEM format. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Create

`azion create crl` uploads a CRL from a PEM file and stores it in Certificate Manager:

```bash
azion create crl [flags]
```

| Flag       | Short | Type   | Default | Description                                                                                                                         |
| ---------- | ----- | ------ | ------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `--active` | —     | string | —       | Marks the CRL as active with `true`.                                                                                                |
| `--crl`    | —     | string | —       | **Required** unless `--file` is set. Path to the file that holds the CRL, in PEM format. Without it, the command asks for the path. |
| `--file`   | —     | string | —       | Path to a JSON file with the attributes of the CRL. Use `-` to read the JSON from standard input.                                   |
| `--issuer` | —     | string | —       | Issuer of the CRL.                                                                                                                  |
| `--name`   | —     | string | —       | Name of the CRL.                                                                                                                    |

This command uploads the CRL in `./certs/list.crl` as an active CRL named `my-crl`, issued by `example.com`:

```bash
azion create crl --name my-crl --issuer example.com --crl ./certs/list.crl --active true
```

The command prints the ID of the CRL:

```text
Created Certificate Revocation List with ID 1236
```

A file that does not hold a CRL, such as a certificate, is refused, and the command fails with this error:

```text
Error: Failed to create the Certificate Revocation List: ["Invalid CRL data."]. Check your settings and try again. If the error persists, contact Azion support
```

---

## List

`azion list crl` lists the CRLs of your account, 50 to a page:

```bash
azion list crl [flags]
```

| Flag          | Short | Type   | Default | Description                                                                                                                            |
| ------------- | ----- | ------ | ------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| `--details`   | —     | —      | —       | Adds the `ACTIVE`, `LAST UPDATE`, `NEXT UPDATE`, `LAST EDITOR`, and `LAST MODIFIED` columns to the `ID`, `NAME`, and `ISSUER` columns. |
| `--filter`    | —     | string | —       | Name to filter the list by.                                                                                                            |
| `--order-by`  | —     | string | —       | Field to sort the list by.                                                                                                             |
| `--page`      | —     | int    | `1`     | Number of the page to return.                                                                                                          |
| `--page-size` | —     | int    | `50`    | Number of CRLs on each page.                                                                                                           |

This command returns the first page of a list split into pages of one CRL:

```bash
azion list crl --page 1 --page-size 1
```

The command prints one row per CRL:

```text
ID    NAME    ISSUER
1236  my-crl  example.com
```

---

## Describe

`azion describe crl` prints the attributes of one CRL:

```bash
azion describe crl [flags]
```

| Flag       | Short | Type | Default | Description                |
| ---------- | ----- | ---- | ------- | -------------------------- |
| `--crl-id` | —     | int  | —       | ID of the CRL to describe. |

This command describes the CRL with ID `1236`:

```bash
azion describe crl --crl-id 1236
```

The command prints the attributes of the CRL, then the CRL itself in PEM format under a `CRL:` line. The excerpt below ends before the PEM content:

```text
ID:                1236
Name:              my-crl
Active:            true
Last Editor:       you@example.com
Created At:        "2026-01-01T12:00:09.378356Z"
Last Modified:     "2026-01-01T12:00:09.378356Z"
Product Version:   1.0
Issuer:            example.com
Last Update:       "2026-01-01T12:00:00Z"
Next Update:       "2026-01-31T12:00:00Z"
```

The `Last Update` and `Next Update` values come from the CRL file, not from a flag. With `--format json`, the command prints the full object: `active`, `created_at`, `crl`, `id`, `issuer`, `last_editor`, `last_modified`, `last_update`, `name`, `next_update`, and `product_version`.

---

## Update

`azion update crl` changes the name or the content of a CRL:

```bash
azion update crl [flags]
```

| Flag       | Short | Type   | Default | Description                                                                                      |
| ---------- | ----- | ------ | ------- | ------------------------------------------------------------------------------------------------ |
| `--active` | —     | string | —       | Sets whether the CRL is active.                                                                  |
| `--crl`    | —     | string | —       | Path to a file with the new CRL, in PEM format.                                                  |
| `--crl-id` | —     | int    | —       | ID of the CRL to update.                                                                         |
| `--file`   | —     | string | —       | Path to a JSON file with the attributes to change. Use `-` to read the JSON from standard input. |
| `--issuer` | —     | string | —       | Issuer of the CRL.                                                                               |
| `--name`   | —     | string | —       | New name of the CRL.                                                                             |

A CRL stays active. With `--active false`, the API refuses the update and the command fails with this error:

```text
Error: Failed to update the Certificate Revocation List: ["You can't disable a Certificate Revocation List(CRL)."]. Check your settings and try again. If the error persists, contact Azion support
```

This command replaces the content of the CRL with ID `1236` with the CRL in `./certs/list.crl`:

```bash
azion update crl --crl-id 1236 --crl ./certs/list.crl
```

The command prints the ID of the updated CRL:

```text
Updated Certificate Revocation List with ID 1236
```

---

## Delete

`azion delete crl` deletes a CRL:

```bash
azion delete crl [flags]
```

| Flag       | Short | Type | Default | Description              |
| ---------- | ----- | ---- | ------- | ------------------------ |
| `--crl-id` | —     | int  | —       | ID of the CRL to delete. |

This command deletes the CRL with ID `1237`:

```bash
azion delete crl --crl-id 1237 -y
```

The command confirms the deletion:

```text
Certificate Revocation List 1237 was successfully deleted
```

---

## Use a JSON file

`azion create crl` and `azion update crl` read the attributes of the CRL from a JSON file with `--file`. Inside the file, `crl` is not a path: it holds the PEM text of the CRL as one JSON string, with each line break written as `\n`.

This file creates an active CRL named `my-other-crl`. The command reads `name`, `issuer`, `crl`, and `active` from it. Replace `<pem-encoded-crl>` with the content of your CRL file:

```json
{
  "name": "my-other-crl",
  "issuer": "example.com",
  "crl": "<pem-encoded-crl>",
  "active": true
}
```

Pass the file to the create command:

```bash
azion create crl --file crl-create.json
```

The command prints the ID of the CRL:

```text
Created Certificate Revocation List with ID 1237
```

On update, pass the ID of the CRL with `--crl-id`. This file renames the CRL with ID `1237`:

```json
{
  "name": "my-other-crl-updated"
}
```

Pass the file to the update command:

```bash
azion update crl --crl-id 1237 --file crl-update.json
```

The command prints the ID of the updated CRL. The name changes, and the CRL stays active:

```text
Updated Certificate Revocation List with ID 1237
```

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates.md): The fields of a CRL, its size limit, and how a workload with mTLS uses it.
- [Azion CLI digital-certificate](/en/documentation/devtools/cli/resources/digital-certificate.md): The commands that upload and manage the certificates Certificate Manager stores.
- [Azion CLI csr](/en/documentation/devtools/cli/resources/csr.md): The commands that create and manage certificate signing requests in Certificate Manager.
