Ever-growing CRL?
Ever-growing CRL?
Posted Dec 7, 2024 14:09 UTC (Sat) by mcatanzaro (subscriber, #93033)In reply to: Ever-growing CRL? by tialaramex
Parent article: Let's Encrypt sets date for ending OCSP support
I don't think that's a great argument in support of OneCRL, because the end result is zero certificate revocation support for anybody who's not using the one or two applications that support the weird proprietary CRLs. Almost everything on your desktop is using GnuTLS or maybe OpenSSL and they simply do not implement nonstandard stuff.
I also don't think that's a even valid argument against OCSP stapling, since stapling is not mandatory, and theoretically only servers that support it properly would ever opt in.
