Ever-growing CRL?
Ever-growing CRL?
Posted Dec 6, 2024 13:52 UTC (Fri) by paulj (subscriber, #341)In reply to: Ever-growing CRL? by dskoll
Parent article: Let's Encrypt sets date for ending OCSP support
You're almost certainly already doing a lookup for the name to find an address mapping anyway, if you're interested in whether a certificate has expired or not. "What's the status of cert for X?" doesn't leak any information of note over the "What's the address of X?" query likely already made.
So, you almost certainly already have that information leak. And if you care about information leaks, then you already have taken steps that fix that leak for /any query/. (E.g., DoH to a varied set of DoH servers, over ToR or other anonymising overlay - my personal machines are setup for dnscrypt for DoH over Tor).
