All Products
Search
Document Center

Certificate Management Service:Revoke a private certificate

Last Updated:Mar 31, 2026

Revoke a private certificate before it expires when you no longer need it.

Warning

Revoking or deleting a private certificate removes trust in your enterprise's internal environments. Revoked certificates cannot be restored or re-enabled. Proceed with caution.

Prerequisites

Before you begin, ensure that you have:

Revoke a certificate

  1. Log in to the Certificate Management Service console.

  2. In the left navigation pane, choose Certificate Management > Private Certificate Management. On the Private Certificate Management page, select the region where the Private Certificate Authority (PCA) service is located.

  3. On the Private CAs tab, find the intermediate CA that issued the certificate, then click Certificates in the Actions column.

  4. On the Certificates page, find the certificate to revoke, then click Revoke in the Actions column.

  5. In the Confirmation message, click Revoke.

The certificate status changes to Revoke immediately. Once revoked, the certificate is no longer trusted in your enterprise's internal environments, and you can delete it from the certificate list.