SSCP Systems Security Certified PractitionerCryptographyHard

A security engineer is designing a system that uses a Public Key Infrastructure (PKI) to manage digital certificates. They need to ensure that when a certificate is revoked, all relying parties are quickly and efficiently informed of its invalidation. Which method provides the most timely and resource-efficient way to check the revocation status of a single certificate in real-time?

  1. ACertificate Revocation List (CRL) distribution point
  2. BOnline Certificate Status Protocol (OCSP)
  3. CManual certificate verification
  4. DTrust Anchor distribution
Show answer & explanation

Correct answer: B. Online Certificate Status Protocol (OCSP)

OCSP (Online Certificate Status Protocol) provides real-time, lightweight status checks for individual certificates. Instead of downloading a potentially large CRL, a client sends a request for a specific certificate's status to an OCSP responder, which returns a signed response indicating 'good,' 'revoked,' or 'unknown.' This is more efficient and timely than CRLs for single certificate checks.

Why the other options are wrong

  • A. CRLs can be large and are updated periodically, meaning they might not reflect the most current revocation status immediately.
  • C. Manual verification is impractical and prone to error for automated systems and large-scale operations.
  • D. Trust Anchor distribution (e.g., root certificates) establishes initial trust but doesn't provide real-time revocation status.

Online Certificate Status Protocol (OCSP)

A protocol used to obtain the revocation status of an X.509 digital certificate in real-time. Clients query an OCSP responder for the status of a specific certificate, receiving a signed response.

  • Provides real-time certificate revocation status.
  • More efficient than CRLs for single certificate checks.
  • Reduces network overhead compared to downloading large CRLs.

Memory trick: OCSP is like asking a quick 'Is this ID still valid?' instead of reading a whole 'invalid IDs' book.

More Cryptography questions