|
|
Log in / Subscribe / Register

Ever-growing CRL?

Ever-growing CRL?

Posted Dec 7, 2024 14:09 UTC (Sat) by mcatanzaro (subscriber, #93033)
In reply to: Ever-growing CRL? by tialaramex
Parent article: Let's Encrypt sets date for ending OCSP support

I don't think that's a great argument in support of OneCRL, because the end result is zero certificate revocation support for anybody who's not using the one or two applications that support the weird proprietary CRLs. Almost everything on your desktop is using GnuTLS or maybe OpenSSL and they simply do not implement nonstandard stuff.

I also don't think that's a even valid argument against OCSP stapling, since stapling is not mandatory, and theoretically only servers that support it properly would ever opt in.


to post comments

Ever-growing CRL?

Posted Dec 16, 2024 5:14 UTC (Mon) by NYKevin (subscriber, #129325) [Link]

> I don't think that's a great argument in support of OneCRL, because the end result is zero certificate revocation support for anybody who's not using the one or two applications that support the weird proprietary CRLs.

Speaking as a Google employee who has no direct involvement with Chrome or Chromium, I would not describe OneCRL as "proprietary" when it has two independent FOSS client implementations. If other FOSS applications do not want to take code from Chromium or Firefox, that's a valid choice for them to make, but it does not mean that OneCRL is proprietary.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds