If the PKI organization's CRL is not available from a central distribution point, you can add the PKI organization's CRL manually to the local certrldb database. Follow the PKI organization's instructions for extracting the CRL, then add the CRL to the database with the ikecert certrldb –a command.
# ikecert certrldb -a Press the Return key Paste the CRL from the PKI organization Press the Return key Press <Control>-D to enter the CRL into the database |