Which three statements about PKI on Cisco IOS Software are true?

Which three statements about PKI on Cisco IOS Software are true? (Choose three.)
A. OCSP is well-suited for enterprise PKIs in which CRLs expire frequently.
B. The match certificate and allow expired-certificate commands are ignored unless the router clock is set.
C. If a certificate-based ACL specifies more than one field, any one successful field-to-value fest is treated as a match.
D. OCSP enables a PKI to use a CRL without time limitations.
E. Certificate-based ACLs can be configured to allow expired certificates if the peer is otherwise valid.
F. Different OCSP servers can be configured for different groups of client certificates .

cisco-exams

One thought on “Which three statements about PKI on Cisco IOS Software are true?

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.