PrepAway - Latest Free Exam Questions & Answers

Which is NOT a suitable method for distributing certifi…

Which is NOT a suitable method for distributing certificate revocation information?

PrepAway - Latest Free Exam Questions & Answers

A.
CA revocation mailing list

B.
Delta CRL

C.
OCSP (online certificate status protocol)

D.
Distribution point CRL

Explanation:
A CA revocation mailing list is NOT a suitable method for distributing certificate revocation information.
There are several mechanisms to represent revocation information; RFC 2459 defines one such method. This
method involves each CA periodically issuing a signed data structure called a certificate revocation list (CRL). A
CRL is a time stamped list identifying revoked certificates, which is signed by a CA and made freely available in
a public repository.
There are several types of CRLs: full CRLs (also known as base CRLs), delta CRLs, and CRL Distribution
Points (CDPs). Full CRLs contain the status of all certificates. Delta CRLs contain only the status of all
certificates that have changed status between the issuance the last Base CRL.
CRL Distribution Point (CDP) is a certificate extension that indicates where the certificate revocation list for a
CA can be retrieved. This extension can contain multiple HTTP, FTP, File or LDAP URLs for the retrieval of the
CRL.
Online Certificate Status Protocol (OCSP) is a protocol that allows real-time validation of a certificate’s status by
having the CryptoAPI make a call to an OCSP responder and the OCSP responder providing an immediate
validation of the revocation status for the presented certificate. Typically, the OCSP responder uses CRLs for
retrieving certificate status information.
Incorrect Answers:
B: A Delta CRL is a suitable method for distributing certificate revocation information.
C: OCSP (online certificate status protocol) is a suitable method for distributing certificate revocation
information.
D: Distribution point CRL is a suitable method for distributing certificate revocation information.

https://technet.microsoft.com/en-us/library/cc700843.aspx


Leave a Reply