Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Indeed! I forgot that the BRs mandate the CRLDP extension if the certificate lacks OCSP AIA.

So all (non-short-lived) certificates will continue to have a standard revocation checking mechanism encoded in them.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: