Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Ping Identity PAP-001 Exam - Topic 3 Question 12 Discussion

A company uses an internally based legacy PKI solution that does not adhere to the Certification Path Validation section of RFC-5280. Which configuration option needs to be enabled when creating Trusted Certificate Groups in PingAccess?
B) Validate disordered certificate chains
A) Use Java Trust Store
C) Skip Certificate Date Check
D) Deny when unable to determine revocation status

Ping Identity PAP-001 Exam - Topic 3 Question 12 Discussion

Actual exam question for Ping Identity's PAP-001 exam
Question #: 12
Topic #: 3
[All PAP-001 Questions]

A company uses an internally based legacy PKI solution that does not adhere to the Certification Path Validation section of RFC-5280. Which configuration option needs to be enabled when creating Trusted Certificate Groups in PingAccess?

Show Suggested Answer Hide Answer
Suggested Answer: B

Legacy PKIs often provide certificate chains that are out of order or non-compliant with RFC-5280 path validation. PingAccess provides an option in Trusted Certificate Groups called Validate disordered certificate chains to allow chaining even if the order is not RFC-5280 compliant.

Exact Extract:

''Enable Validate disordered certificate chains when the certificate chain is not in RFC-5280 compliant order but should still be accepted.''

Option A is incorrect; using the Java trust store is unrelated to PKI ordering.

Option B is correct --- this setting allows PingAccess to process disordered certificate chains.

Option C is incorrect; date checks are unrelated to RFC-5280 path ordering.

Option D is incorrect; revocation status handling does not address legacy PKI ordering issues.


Contribute your Thoughts:

0/2000 characters
Virgie
5 hours ago
I think option B is the best choice. It helps with the legacy PKI issue.
upvoted 0 times
...
Ashley
5 days ago
Can someone explain why we wouldn't want to deny on revocation status?
upvoted 0 times
...
Aileen
11 days ago
Definitely B) is needed for legacy systems like this.
upvoted 0 times
...
Skye
16 days ago
Wait, are we really skipping certificate date checks? That sounds risky!
upvoted 0 times
...
Jamal
2 months ago
I disagree, I think A) Use Java Trust Store is more relevant here.
upvoted 0 times
...
Yuki
2 months ago
B) Validate disordered certificate chains is the right choice.
upvoted 0 times
...
Angelica
3 months ago
I practiced a similar question where revocation status was crucial, so I wonder if denying when unable to determine revocation status could be a key factor here.
upvoted 0 times
...
Dalene
3 months ago
I feel like skipping the certificate date check could lead to security risks, so it probably isn't the right option.
upvoted 0 times
...
Wayne
3 months ago
I'm not entirely sure, but I remember something about the Java Trust Store being important for legacy systems. Maybe that's the answer?
upvoted 0 times
...
Kara
4 months ago
I think the option about validating disordered certificate chains might be the right choice since the legacy PKI could have issues with the order of certificates.
upvoted 0 times
...

Save Cancel