SSCP Systems Security Certified PractitionerCryptographyMedium
A security auditor is examining a client's Certificate Revocation List (CRL) distribution points. The auditor notices that the CRLs are updated only once every 24 hours. Given this update frequency, what is the maximum window of vulnerability for a revoked certificate before its status is officially published to all relying parties?
- AImmediately, if using OCSP
- BIndefinitely until the next update
- CLess than 1 hour
- DUp to 24 hours
Show answer & explanationAnswer & explanation
Correct answer: D. Up to 24 hours
If a CRL is updated every 24 hours, any certificate revoked between updates will remain valid (from the perspective of the CRL) for up to 24 hours until the next CRL is published and distributed to relying parties.
Why the other options are wrong
- A. OCSP (Online Certificate Status Protocol) provides near real-time status, but the question specifically mentions CRLs.
- B. The certificate is not valid indefinitely; it will be listed in the next CRL update, but there is a specific maximum window of vulnerability.
- C. Less than 1 hour is incorrect; the update frequency is explicitly stated as 24 hours.
Certificate Revocation List (CRL)
A list of digital certificates that have been revoked by the issuing Certificate Authority (CA) before their scheduled expiration date.
- Periodically published by the CA.
- Must be checked by relying parties to confirm certificate validity.
- Can lead to a window of vulnerability between publications.
Memory trick: CRL updates are like slow newspaper deliveries; news of a bad cert can take a full cycle to spread.