How does certificate revocation work in PKI?

Certificate revocation ensures that compromised or invalid certificates are no longer trusted.

Revocation occurs when:

  • A private key is compromised
  • The certificate holder’s status changes
  • Incorrect information was issued

The CA updates Certificate Revocation Lists (CRL) or Online Certificate Status Protocol (OCSP) responses. Systems automatically check revocation status before trusting a certificate, maintaining ongoing integrity and trust.