LWN.net Logo

CAs say few people are getting replacements

CAs say few people are getting replacements

Posted Jun 16, 2008 19:11 UTC (Mon) by flewellyn (subscriber, #5047)
In reply to: CAs say few people are getting replacements by endecotp
Parent article: SSL Certificates Vulnerable to OpenSSL Flaw on Debian (Netcraft)

I just looked up your question regarding revocation.  Yes, the CAs can and should issue a
revocation list of vulnerable certificates.  The X.509 certificate standard provides for such
a capability.  

That the CAs haven't used it yet indicates they aren't taking this problem as seriously as
they should.


(Log in to post comments)

CAs say few people are getting replacements

Posted Jun 17, 2008 2:41 UTC (Tue) by ringerc (subscriber, #3071) [Link]

As far as I know most user-agents don't support, or check, a CRL. From what I've seen support
generally requires user/admin configuration and mostly seems to get used on SOE setups and
corporate intranets.

CAs say few people are getting replacements

Posted Jun 20, 2008 16:43 UTC (Fri) by akumria (subscriber, #7773) [Link]

I think OSCP would do what you are after.

It is part of Firefox 3.0, so it probably fairly widely deployed (by now).

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds