Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

https://groups.google.com/forum/#!searchin/mozilla.dev.secur... for example (3 years old).

The right keyword to search for is OCSP, because CRLs are completely impractical in the browser.

But then we have the issue that OCSP is a pretty retarded protocol. OCSP stapling helps with some issues, but there is still the issue that it doesn't really check if a certificate is valid, but whether a certificate bearing the given serial number is valid. Which didn't help AT ALL when using MD5 collisions people managed to create multiple certificates under the same serial number.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: