Hacker News new | ask | show | jobs
by eqvinox 701 days ago
Wait. What. Let's Encrypt CRLs are only available to browser vendors? So you can't even do a CRL check in an SMTP server if you wanted to?

> Our new CRL URLs will be disclosed only in CCADB, so that the Apple and Mozilla root programs can consume them without exposing them to potentially large download traffic from the rest of the internet at large.

https://letsencrypt.org/2022/09/07/new-life-for-crls.html

1 comments

That’ll change with OCSP depreciation, as certificates are required to contain one or the other of OCSP or CRLs.