|
|
|
|
|
by einhverfr
4450 days ago
|
|
Ok, fair enough. I am just making sure my objection to Google's approach is clear. I would be OK if they guaranteed complete CRLsets from all participating CA's. Since they don't, their solution is more broken than what they are replacing. So I acknowledge that online revocation is problematic. I just think the crlset approach is an order of magnitude worse when the crlset is a subset of revoked entries sent by the ca. |
|