Revocation of digital certificates: CRL, OCSP, OCSP stapling

Поділитися
Вставка
  • Опубліковано 17 січ 2025

КОМЕНТАРІ • 80

  • @michaeljimenez239
    @michaeljimenez239 Рік тому +2

    Just want to say, i used some of your videos to pass my network plus and currently doing th same with security plus. I always find your explanations easier to understand than most other instructors. Thank you!

  • @johnhart6320
    @johnhart6320 5 років тому +19

    As ALWAYS...your videos help me BIGTIME! Whenever I am in need of a CLEAR explanation on a technology that some other 'Off the Charts GEEK in the Weeds' tries to teach, I check and see if Sunny has a class to clear it up for me! Thanks Again Man!!

    • @sunnyclassroom24
      @sunnyclassroom24  5 років тому +6

      Thank you, John, for saying nice things about my videos. You are welcome. I wish I would complete my whole series in this area (about 200 videos) soon.

  • @MohenjinAdventure
    @MohenjinAdventure 4 роки тому +5

    I could not understand about CRL/OCSP/OSCP Stapling, but now I finally did. Thank you! You have been a great help!

  • @lesleycouch9542
    @lesleycouch9542 Рік тому

    I knew I could count on you to explain this concept clearly and concisely. I get it now! Thank you Sunny!

  • @miriyalajeevankumar5449
    @miriyalajeevankumar5449 4 роки тому +1

    The best content on this topic is your channel !!

  • @nattiyar614
    @nattiyar614 4 роки тому +2

    This is by far the best explanation ever! Thank you so much!!

  • @scottbiggs8894
    @scottbiggs8894 4 роки тому +3

    Step 4, that all this happens "during the SSL/TLS handshake" was the puzzle piece I was missing. Thank you. And the music at end made me laugh. :)

  • @chengluo5956
    @chengluo5956 4 роки тому +3

    Simple and clear, that's all I need. Thank you Sunny!

  • @TheSukramb
    @TheSukramb 5 років тому +1

    Truly awesome. Helps a lot because of your visualizations in addition to your explanation.

  • @techlearner4806
    @techlearner4806 9 місяців тому

    Simple and easy language/demo used in video. All thanks to you.

  • @poncho8887
    @poncho8887 8 місяців тому

    Thank you for your clear explanations for our understanding.

  • @jilanishaik8791
    @jilanishaik8791 4 роки тому +1

    It's very nice explanation. Thanks Sunny

  • @jaydawg91
    @jaydawg91 3 роки тому

    As always your videos are clear and provide accurate information. Thank you, Sunny.

  • @nkanakaraj
    @nkanakaraj 2 роки тому

    Awesome! This is the exact info I was looking for to troubleshoot an issue related to OSCP. Sunny! you very well explained CRL, OSCP, and OSCP-Stapling operations in a quick video. Thank you very much!

  • @ayatarek6612
    @ayatarek6612 3 роки тому +1

    Thank you so much this was very clear and helpful.

  • @TheAhamedabdul
    @TheAhamedabdul 4 роки тому +1

    Thanks a lot Sunny! this is very clear and useful.

  • @okbazoueghi6714
    @okbazoueghi6714 3 роки тому +1

    Great explanation!

  • @sonurocks341
    @sonurocks341 4 роки тому +1

    Great Videos. Very crisp explanation.

  • @AmeenAltajer
    @AmeenAltajer 3 роки тому +1

    Clear explanation, thanks man!

  • @jasonhoi85
    @jasonhoi85 4 роки тому +1

    thanks this is much clean then reading the text explaination

  • @nicholasbarning8250
    @nicholasbarning8250 5 років тому +2

    Excellent videos, very concise and easy to understand. Thank you

  • @marcosalameh8677
    @marcosalameh8677 3 роки тому

    As usual soooooooo amazing!!!!!!!!!!!!!!!!!!!!!

  • @34521ful
    @34521ful 6 років тому +2

    Hi Sunny, great video once again! I think one thing I'd add for future viewers is that another thing browsers like Firefox and Chrome do are just push a software update if a certificate must be revoked as soon as possible

    • @sunnyclassroom24
      @sunnyclassroom24  6 років тому +2

      thanks a lot for your information. I appreciate it very much.

  • @tim6925
    @tim6925 Рік тому

    thank you, thats a very clear explanation.

  • @HughJass-313
    @HughJass-313 3 роки тому +1

    Bravo!!
    ❤❤

  • @asoteico9528
    @asoteico9528 4 роки тому +1

    Greatly done Sunny...!!!
    🥇🎖🏅

  • @aziz421973
    @aziz421973 6 років тому +3

    Very useful information, thank you so much.

  • @andreaszetea-ster900
    @andreaszetea-ster900 5 років тому +2

    great work. Thank you

  • @zowajoy7616
    @zowajoy7616 4 роки тому +1

    You are awesome 🙏

  • @Drawmeafatcat
    @Drawmeafatcat 3 роки тому

    crazy how complicated other people make this when you just explained it in 6 mins.

  • @ravichanderkt326
    @ravichanderkt326 Рік тому

    You're Gifted By God.

  • @jeremygunter9877
    @jeremygunter9877 7 місяців тому

    Well done, thank you!

  • @johnnkoh2601
    @johnnkoh2601 4 роки тому

    you are really good at explaining things. Thank you very much

  • @ahmeddarwish3859
    @ahmeddarwish3859 3 роки тому

    very good teacher.Thanks

  • @livestronger1981
    @livestronger1981 3 роки тому

    Great explanation

  • @devendramhatre5007
    @devendramhatre5007 4 роки тому +1

    Nicely Explained....
    thank you sir

  • @grahammattingley9784
    @grahammattingley9784 6 років тому +1

    Very helpful information - keep up the good videos and the good work

  • @AyushmanAdhikary
    @AyushmanAdhikary 3 роки тому

    Great video. Thanks for the explanation.

  • @rajeshgeorge6093
    @rajeshgeorge6093 4 роки тому +1

    thanks very much

  • @kavi3841
    @kavi3841 4 роки тому +1

    Thank you sir

  • @OmarJIBAR
    @OmarJIBAR 2 роки тому

    Beautiful 👌

  • @mimi7132
    @mimi7132 3 роки тому

    great explanation, thanks

  • @fa307
    @fa307 2 роки тому

    great video, would be great if you could update this and make a video about certificate transparency (CT Logs)! :)

  • @jibnathgautamhy1280
    @jibnathgautamhy1280 4 роки тому

    Thank you verymuch

  • @dieglhix
    @dieglhix 4 роки тому +1

    All clear, thanks Mr. Subscribing now.

  • @corolla1209
    @corolla1209 4 роки тому

    Hi Sunny, will you talk about SCVP in the future videos?

  • @mofogie
    @mofogie 4 роки тому +2

    well what if a domain spoofer simply forges a certificate?

  • @iyam1513
    @iyam1513 2 роки тому

    Thanks for your video, "OCSP stapling" is quite smart solution, but for how long does web server cache OCSP Response from CA? And for how long does the client (browser) consider that the response is still valid (I mean as for standards)?
    I think this is the point of "lag" between revocation and outdated signed OCSP Response from web server. So it is important to note.

  • @arber10
    @arber10 6 років тому +2

    Sunny, one more question: Which book(s) would you recommend for a deep dive in this topic? (I mean cryptography not just revocation.)

    • @sunnyclassroom24
      @sunnyclassroom24  6 років тому +2

      It depends how deep do you want to go? If you are just for CompTIA security + , you can use Comptia security+ guide to network security fundamentals 6th edition or 5th edition (cheaper).

    • @arber10
      @arber10 6 років тому

      Thank you. I will check this.

  • @deekusnotes3318
    @deekusnotes3318 Рік тому

    Does it mean OCSP URLs no need to be added to firewall between client and server?

  • @greenboy7484
    @greenboy7484 6 років тому +1

    hi sunny...can you explain how policy maping works in CA and sub-CA in another video?

  • @sriksrik8184
    @sriksrik8184 3 роки тому

    Hi Sunny, if the client from a ABC company domain accessing a website, how can it check the website certificates status from the ABC domains CA CRL list,,, does that mean that ABC domain CA will have constant updates, if so how,,,

  • @ishajain7020
    @ishajain7020 6 років тому +2

    When certificates are stolen from CA, why those certificates need to be revoked. I mean we are already certificates, but harm stolen certificates will make.

    • @sunnyclassroom24
      @sunnyclassroom24  6 років тому +3

      Browsers make sure that all certificates are valid. It is like someone stole your credit card, and you want to report to your credit card company to revoke it. Otherwise, the thief will use your credit card. The same thing.

    • @RajivKumar-ee7xv
      @RajivKumar-ee7xv 3 роки тому +1

      @@sunnyclassroom24Here I have a question, Private key of stolen certificate is always with the owner for whom CA issued certificate. So other details are always public. What was stolen from CA for that particular certificate?

  • @ameenasif
    @ameenasif 2 роки тому

    So if an organization has issued certificates in thousands , and device1 comes with request , does webserver has stapled request for all thousand devices at that time , if its cached only on calls ? so when a signed response is received all it needs to do is verify certificate validity end date etc, no need to go to check revoked status as its trusted with cryptography i.e the signed response . is this right

  • @chadsexinton
    @chadsexinton 2 роки тому

    Yea but browser and other clients no longer check the crl or ocsp servers so revocation is useless .

  • @richardturk7162
    @richardturk7162 4 роки тому

    Great explanation but I still have no idea what you are talking about.

  • @DohertyMax
    @DohertyMax 4 місяці тому

    Lopez Barbara Young Jessica White David

  • @dr.r.aravindhanm.eph.d1046
    @dr.r.aravindhanm.eph.d1046 2 роки тому

    Very Good Explanation