CompTIA Security+ (SY0-701)General Security ConceptsHard
A browser needs to verify in real time whether a website's certificate has been revoked, without downloading a large revocation list. Which protocol is used for this purpose?
- ACRL
- BLDAP
- CSCEP
- DOCSP
Show answer & explanationAnswer & explanation
Correct answer: D. OCSP
The Online Certificate Status Protocol (OCSP) allows a client to query a certificate authority in real time for the revocation status of a single certificate, avoiding the need to download an entire certificate revocation list (CRL).
Why the other options are wrong
- A. CRL requires downloading a full list of revoked certificates, which the scenario says to avoid.
- B. LDAP is a directory access protocol unrelated to certificate revocation checking.
- C. SCEP is used for certificate enrollment, not revocation status checking.
OCSP
Online Certificate Status Protocol; allows real-time verification of an individual certificate's revocation status from a CA.
- Faster and lighter than downloading a full CRL
- OCSP stapling lets the web server provide the response, improving privacy and performance
- Response is signed by the CA or an authorized responder
Memory trick: OCSP = On-demand Check, Single Piece