Ever-growing CRL?
Ever-growing CRL?
Posted Dec 6, 2024 15:51 UTC (Fri) by dskoll (subscriber, #1630)In reply to: Ever-growing CRL? by paulj
Parent article: Let's Encrypt sets date for ending OCSP support
You're almost certainly already doing a lookup for the name to find an address mapping anyway
Oh sure. You're leaking that info to your name servers, your ISP's name servers maybe, and all the servers along the chain up to the root of the domain you're looking up.
You're not leaking the info to some third-party that maintains the list of revoked certificates.
