Certificates have an expiration date, but sometimes a certificate must stop being trusted before then. The private key may have been stolen, the domain sold, the employee who held it may have left, or the CA may have issued it by mistake. Revocation is how a CA announces 'do not trust this certificate any more'. It matters because a stolen private key with a still-trusted certificate lets an attacker impersonate a site or person perfectly until the certificate is revoked and clients actually check. Security+ tests the two main checking methods and the improvement called OCSP stapling. A related idea is certificate suspension, sometimes called a hold, which temporarily marks a certificate as untrusted and can later be lifted, whereas revocation is permanent.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.