Every PKI eventually has to answer the same operational question: when a client needs to know whether a certificate has been revoked, how does it find out, quickly, reliably, and without unnecessary overhead? Certificate Revocation Lists, covered in depth elsewhere in this series, were the original answer. The Online Certificate Status Protocol, OCSP, emerged as a more real-time alternative. This article compares the two directly and looks at where each fits in a modern PKI.