A security engineer is designing a system that uses a Public Key Infrastructure (PKI) to manage digital certificates. They need to ensure that when a certificate is revoked, all relying parties are quickly and efficiently informed of its invalidation. Which method provides the most timely and resource-efficient way to check the revocation status of a single certificate in real-time?
- ACertificate Revocation List (CRL) distribution point
- BOnline Certificate Status Protocol (OCSP)
- CManual certificate verification
- DTrust Anchor distribution
Show answer & explanationAnswer & explanation
Correct answer: B. Online Certificate Status Protocol (OCSP)
OCSP (Online Certificate Status Protocol) provides real-time, lightweight status checks for individual certificates. Instead of downloading a potentially large CRL, a client sends a request for a specific certificate's status to an OCSP responder, which returns a signed response indicating 'good,' 'revoked,' or 'unknown.' This is more efficient and timely than CRLs for single certificate checks.
Why the other options are wrong
- A. CRLs can be large and are updated periodically, meaning they might not reflect the most current revocation status immediately.
- C. Manual verification is impractical and prone to error for automated systems and large-scale operations.
- D. Trust Anchor distribution (e.g., root certificates) establishes initial trust but doesn't provide real-time revocation status.
Online Certificate Status Protocol (OCSP)
A protocol used to obtain the revocation status of an X.509 digital certificate in real-time. Clients query an OCSP responder for the status of a specific certificate, receiving a signed response.
- Provides real-time certificate revocation status.
- More efficient than CRLs for single certificate checks.
- Reduces network overhead compared to downloading large CRLs.
Memory trick: OCSP is like asking a quick 'Is this ID still valid?' instead of reading a whole 'invalid IDs' book.