About this interactive
PKI was designed so your computer can verify a certificate on its own, using the root certificate it already has, without waiting on the certificate authority. That is also its weak spot. If a site's private key is stolen, the certificate is compromised, yet the local check still passes. Revocation is how a CA tells you a certificate should no longer be trusted, before it expires.
A certificate revocation list (CRL) is a list of revoked certificates that the CA keeps. Whoever holds the key notifies the CA, the CA adds the certificate to the list, and your computer downloads the list and checks it. Two problems: the list can get large, which makes a site seem slow, and your copy is out of date as soon as you download it, often until it expires and a new one is fetched.
The online certificate status protocol (OCSP) runs at the certificate authority. When your browser gets a new certificate, it asks a quick question about that one certificate, is it still good, and gets back a yes or a no. It is much more dynamic than a list. It can still be slow, and if no answer comes back, the browser will probably assume the certificate is valid and connect.
Then there is no check at all. Many browsers do neither: they validate the certificate against the root and connect. So a revoked certificate can still be accepted, which is why the lesson ends where it starts: keep private keys private.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →