Hacker News new | ask | show | jobs
by papaf 4436 days ago
Theres one thing that I do not understand - why not download the full revocation list?
2 comments

Potentially too much data to download, imagine, all revoked certificates in the entire internet.
You would have to crawl all OCSP providers on the internet to generate the list.