Hacker News new | ask | show | jobs
by warhorse10_9 702 days ago
Modern crls are partitioned so this really isn’t a problem you will run into.
1 comments

Does that not recreate the privacy problem then, since the CRL server can see which CRL partition we download and when?

Should we expect CRL stapling?

I think one would expect a partition to cover a lot of certificates for its size (or in the case of a compromise all certificates mapped to that partition) so I don't think you end up with nearly so meaningful a problem.