Revoke
You can revoke a user's card if it is damaged, lost or compromised.
caution
If you enabled the Revoke certificate at card revoking/disabling option in the CA certificate template settings, all certificates stored on a card are removed.
To revoke a card:
- Navigate to the user's profile.
- Select the required card and then select Revoke in the card menu.
- Define the revocation reason:
- Card broken — the card is broken or destroyed.
- Card lost — the card is lost or stolen. If you select this reason, all certificates stored on the card are automatically revoked.
- Card replacement — the card is replaced with a new one.
- Card withdraw — the card is withdrawn from a deactivated user.
- Card compromise — the card key is suspected to be compromised. If you select this reason, all certificates on the card are automatically revoked.
- Connect the card to the workstation and click Revoke. If you do not have access to the card, assign a task on the client agent: enable the Clear card on agent option.
The card revocation reason is displayed in the user's profile. If a user tries to authenticate with a revoked card, they receive a message stating that the certificates have been revoked.
Allow users to revoke cards in the Self-Service
You can allow or prevent users from revoking cards in the Self-Service. To configure the permission:
- Open the Configuration section, navigate to the policy settings and go to Workflow → User permissions → Issued card operations.
- Enable the Revoke option.