TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

An analysis of CRL sizes from various CAs

1 pointsby new23d10 months ago

3 comments

new23d10 months ago
Some initial observations:<p>• Google&#x27;s CRLs from the same intermediate CA (same public key) have different URLs and different content when pulled from different hosts (google.com, youtube.com).<p>• DigiCert has sharded according to &#x27;assurance&#x27; class, algorithm, year and acquisition&#x27;s name.<p>• Sectigo also has sharded according to &#x27;assurance&#x27; class [1].<p>• GlobalSign has sharded by the yearly quarter presumably.<p>• HTTP Cache-Control maxage (or s-maxage), &#x27;Expires&#x27; and &#x27;Next Update&#x27; within the CRL file are not in sync.<p>• Some CAs other than Let&#x27;s Encrypt also do not publish CRL URLs in the leaf certificates.<p>[1] <a href="https:&#x2F;&#x2F;www.sectigo.com&#x2F;knowledge-base&#x2F;detail&#x2F;Sectigo-Intermediate-Certificates-ECC&#x2F;kA01N000000rfGE" rel="nofollow">https:&#x2F;&#x2F;www.sectigo.com&#x2F;knowledge-base&#x2F;detail&#x2F;Sectigo-Interm...</a>
new23d10 months ago
We collected some data on the viability of only CRLs as the future (phasing out OCSP) - motivated by Let&#x27;s Encrypt&#x27;s announcement today [1].<p>Data is on CRL availability, number of entries, expiry &amp; refresh times, etc. from various x509 leaf server SSL certificates.<p>[1] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=41046956">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=41046956</a>
threesevenths10 months ago
What analysis was done or are we just talking about the data gathering?
评论 #41061028 未加载