A protocol (RFC 6960) for checking whether a single certificate has been revoked, by querying a responder in real time instead of downloading a full revocation list. Responses are signed by the CA or a delegated responder and can be cached or stapled into a TLS handshake. It complements or replaces CRL checking, trading list downloads for per-certificate queries.
OCSP
Online Certificate Status Protocol