TechKnowSurge
CompTIA Security+ 1.4 CompTIA SecurityX 2.2 Cisco CyberOps Associate 2.10 ISC2 CISSP 3.6 NIST 800-53 SC-12
InteractiveSecurityFree

CRL, OCSP or No Check?

How does the browser learn a certificate was revoked: a downloaded list (CRL), a live question to the CA (OCSP), or not at all? Land five in a row.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

PKI was designed so your computer can verify a certificate on its own, using the root certificate it already has, without waiting on the certificate authority. That is also its weak spot. If a site's private key is stolen, the certificate is compromised, yet the local check still passes. Revocation is how a CA tells you a certificate should no longer be trusted, before it expires. A certificate revocation list (CRL) is a list of revoked certificates that the CA keeps. Whoever holds the key notifies the CA, the CA adds the certificate to the list, and your computer downloads the list and checks it. Two problems: the list can get large, which makes a site seem slow, and your copy is out of date as soon as you download it, often until it expires and a new one is fetched. The online certificate status protocol (OCSP) runs at the certificate authority. When your browser gets a new certificate, it asks a quick question about that one certificate, is it still good, and gets back a yes or a no. It is much more dynamic than a list. It can still be slow, and if no answer comes back, the browser will probably assume the certificate is valid and connect. Then there is no check at all. Many browsers do neither: they validate the certificate against the root and connect. So a revoked certificate can still be accepted, which is why the lesson ends where it starts: keep private keys private.

What you'll learn

Aligned to

CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.
CompTIA SecurityX
2.2 Given a scenario, implement appropriate PKI infrastructure solutions.
Cisco CyberOps Associate
2.10 Describe the impact of certificates on security
ISC2 CISSP
3.6 Select and determine cryptographic solutions
NIST 800-53
SC-12 Cryptographic Key Establishment and Management

Key terms

Certificate Revocation List
CRL
A Certificate Revocation List is a signed, time-stamped list published by a Certificate Authority that identifies digital certificates revoked before their expiration date due to key compromise, CA compromise, or policy violation.
Online Certificate Status Protocol
OCSP
Online Certificate Status Protocol is a real-time alternative to CRL-based revocation checking that allows clients to query a CA's OCSP responder to instantly determine whether a specific certificate is valid, revoked, or unknown.
Private Key
A secret cryptographic key used in asymmetric encryption to decrypt data or create digital signatures.
Certificate Authority
CA
A trusted entity that issues digital certificates used to verify the identity of individuals, organizations, or devices.
Digital Certificate
An electronic document that uses a digital signature to bind a public key with an identity.

Topics

Certificate Revocation Public Key Infrastructure Interactive Streak Sort

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →