In OCSP, Snowflake evaluates each certificate in the chain of trust up to which certificate level?

Master the SnowPro Advanced Architect Test with flashcards, multiple-choice questions, and detailed explanations. Prepare thoroughly for your certification!

Multiple Choice

In OCSP, Snowflake evaluates each certificate in the chain of trust up to which certificate level?

Explanation:
When a TLS connection uses OCSP, you verify that certificates in the presented chain are not revoked, starting with the leaf and moving up through its issuers. The root certificate is a trust anchor that’s assumed valid and is not typically checked for revocation via OCSP. So the highest level you actively validate through OCSP is the intermediate certificate that was issued by the root CA. That means Snowflake confirms the leaf and the immediate issuer (the intermediate certificate) up to that point, anchoring trust with the root. Hence the correct level is the intermediate certificate issued by the root CA.

When a TLS connection uses OCSP, you verify that certificates in the presented chain are not revoked, starting with the leaf and moving up through its issuers. The root certificate is a trust anchor that’s assumed valid and is not typically checked for revocation via OCSP. So the highest level you actively validate through OCSP is the intermediate certificate that was issued by the root CA. That means Snowflake confirms the leaf and the immediate issuer (the intermediate certificate) up to that point, anchoring trust with the root. Hence the correct level is the intermediate certificate issued by the root CA.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy