Lamassu IoT Docs

Revocation lists (CRL)

Generate and distribute signed lists to validate certificates offline.

CRL service

A CRL (Certificate Revocation List) is a signed list containing the serial numbers of certificates revoked before their expiration date. Unlike OCSP, it does not require a real-time query: the relying party downloads the list periodically and consults it locally.

Lamassu generates and maintains one CRL per CA it manages. Each CRL is signed with the private key of the issuing CA itself and is stored in the object storage configured on the platform.

VA role and per-CA configuration

The publication of each CA's CRL is controlled by a VA role. This object defines how it is generated, when it is regenerated and which key signs it.

The main parameters are:

  • validity defines the validity period reflected in nextUpdate. Its default value is 7 days.
  • refresh_interval sets the minimum interval between scheduled regenerations. By default it is approximately 6 days and 23 hours.
  • regenerate_on_revoke orders publishing a new version immediately after a revocation. It is enabled by default.

The subject_key_id_signer field identifies the CA whose private key signs the CRL. By default, each CA signs its own CRL.

Each CRL carries an incremental version number. Lamassu stores all versions under the path pki/va/crl/{subject_key_id}/{version}.crl in object storage.

Periodic and automatic regeneration

A background process monitors active VA roles. When the remaining validity of the current CRL falls below the configured watch period (blind period), the system requests the generation of a new CRL. This prevents the published CRL from expiring without a valid version available.

Additionally, when regenerate_on_revoke is enabled, which is the default behavior, any certificate revocation immediately triggers the generation of a new CRL for the affected CA. This minimizes the time between revocation and its publication.

CRL contents

Each entry of the CRL includes the serial number of the revoked certificate, the revocation date and the RFC 5280 reason code.

The CRL also includes the Issuing Distribution Point (IDP, OID 2.5.29.28) extension, marked as critical, which indicates the public URL from which it can be downloaded. That URL points to the /crl/{subject_key_id} endpoint of each configured VA domain.

Public download endpoint

The latest CRL of a CA can be obtained directly without authentication:

curl https://<LAMASSU_HOST>/crl/<CA_SUBJECT_KEY_ID> -o ca.crl

The response has Content-Type: application/pkix-crl and contains the CRL in DER format.

VA role management API

The VA role of a CA can be queried and updated through the API:

MethodPathDescription
GET/v1/roles/{ca-ski}Returns the VA role configuration and the metadata of the last issued CRL.
PUT/v1/roles/{ca-ski}Updates the VA role configuration parameters (validity, refresh_interval, regenerate_on_revoke).

Example of querying the VA role:

curl https://<LAMASSU_HOST>/v1/roles/<CA_SUBJECT_KEY_ID> \
  -H "Authorization: Bearer <TOKEN>"

The response includes the latest_crl field with the version, the start of validity and the expiration date of the currently published CRL.

From the interface

From a CA's detail panel you can preview the content of the active CRL and download it directly for offline use or for importing into applications that perform local validation.

References

  • RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile

On this page