Hacker News new | ask | show | jobs
by thayne 697 days ago
I did some research a while ago into ensuring up to date CRLs for a non-browser use case. Besides the problem of the massive size of CRLs, I couldn't find good tools for automatic updates across all trusted CRLs.

My conclusion was that it isn't really practical unless you only trust one or two CAs.