Azion CLI crl
Azion CLI commands that create, list, describe, update, and delete certificate revocation lists, with every flag, its type, and its default.
The Azion CLI crl commands create, list, describe, update, and delete certificate revocation lists (CRLs) in Certificate Manager. A CRL is a list of revoked certificates that a Certificate Authority (CA) issues, and the CLI uploads it from a file in PEM format. The options every command accepts, such as --format, --out, and -y, are on Global options.
Create
azion create crl uploads a CRL from a PEM file and stores it in Certificate Manager:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--active | — | string | — | Marks the CRL as active with true. |
--crl | — | string | — | Required unless --file is set. Path to the file that holds the CRL, in PEM format. Without it, the command asks for the path. |
--file | — | string | — | Path to a JSON file with the attributes of the CRL. Use - to read the JSON from standard input. |
--issuer | — | string | — | Issuer of the CRL. |
--name | — | string | — | Name of the CRL. |
This command uploads the CRL in ./certs/list.crl as an active CRL named my-crl, issued by example.com:
The command prints the ID of the CRL:
A file that does not hold a CRL, such as a certificate, is refused, and the command fails with this error:
List
azion list crl lists the CRLs of your account, 50 to a page:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--details | — | — | — | Adds the ACTIVE, LAST UPDATE, NEXT UPDATE, LAST EDITOR, and LAST MODIFIED columns to the ID, NAME, and ISSUER columns. |
--filter | — | string | — | Name to filter the list by. |
--order-by | — | string | — | Field to sort the list by. |
--page | — | int | 1 | Number of the page to return. |
--page-size | — | int | 50 | Number of CRLs on each page. |
This command returns the first page of a list split into pages of one CRL:
The command prints one row per CRL:
Describe
azion describe crl prints the attributes of one CRL:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--crl-id | — | int | — | ID of the CRL to describe. |
This command describes the CRL with ID 1236:
The command prints the attributes of the CRL, then the CRL itself in PEM format under a CRL: line. The excerpt below ends before the PEM content:
The Last Update and Next Update values come from the CRL file, not from a flag. With --format json, the command prints the full object: active, created_at, crl, id, issuer, last_editor, last_modified, last_update, name, next_update, and product_version.
Update
azion update crl changes the name or the content of a CRL:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--active | — | string | — | Sets whether the CRL is active. |
--crl | — | string | — | Path to a file with the new CRL, in PEM format. |
--crl-id | — | int | — | ID of the CRL to update. |
--file | — | string | — | Path to a JSON file with the attributes to change. Use - to read the JSON from standard input. |
--issuer | — | string | — | Issuer of the CRL. |
--name | — | string | — | New name of the CRL. |
A CRL stays active. With --active false, the API refuses the update and the command fails with this error:
This command replaces the content of the CRL with ID 1236 with the CRL in ./certs/list.crl:
The command prints the ID of the updated CRL:
Delete
azion delete crl deletes a CRL:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--crl-id | — | int | — | ID of the CRL to delete. |
This command deletes the CRL with ID 1237:
The command confirms the deletion:
Use a JSON file
azion create crl and azion update crl read the attributes of the CRL from a JSON file with --file. Inside the file, crl is not a path: it holds the PEM text of the CRL as one JSON string, with each line break written as \n.
This file creates an active CRL named my-other-crl. The command reads name, issuer, crl, and active from it. Replace <pem-encoded-crl> with the content of your CRL file:
Pass the file to the create command:
The command prints the ID of the CRL:
On update, pass the ID of the CRL with --crl-id. This file renames the CRL with ID 1237:
Pass the file to the update command:
The command prints the ID of the updated CRL. The name changes, and the CRL stays active: