Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Cryptography & PKI

CRL

Certificate Revocation List

A published list of certificates a CA has revoked before their expiry.

A CRL is a signed list, published periodically by a CA, naming certificates revoked before their natural expiration due to key compromise or other causes. A relying party downloads the list and checks whether a presented certificate appears on it. The main drawbacks are size and latency, since a client may keep trusting a revoked certificate until it fetches the next list. OCSP was introduced to offer a lighter, near real time status check as an alternative.

Memory hook

Certificate Revocation List: the full list of revoked certificates you download and check.

Related terms

Looking CRL up is step one. Getting tested on it is step two.

A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.

Not affiliated with or endorsed by CompTIA.