A network administrator is looking for a way to automatically update company browsers so they
import a list of root certificates from an online source. This online source will then be responsible
for tracking which certificates are to be trusted or not trusted. Which of the following BEST
describes the service that should be implemented to meet these requirements?

A.
Trust model
B.
Key escrow
C.
OCSP
D.
PKI
Why trust model?
Why not OCSP? i think that OCSP it fits better for tracking which certificates are to be trusted or not trusted, and it’s also supported by several browsers.
Or is something that i’m missing here? Can somebody help me please?
0
0
OCSP should be the answer
OCSP: The Online Certificate Status Protocol is an Internet protocol used for obtaining the revocation status of an X.509 digital certificate. It is described in RFC 6960 and is on the Internet standards track
Key word here is online certificates from an online source
0
0