Running Revocation Check-OCSP

A sophisticated method of detecting revoked certificates is the Online Certificate Status Protocol (OCSP). Instead of downloading and parsing the entire CRL, the client can send the certificate in question to the CA. And then, the CA replies status of the certificate is good, revoked, or unknown. This method involves far less overhead than CRL and is also more reliable.