Skip to main content


For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:

  • OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
  • CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
  • Short-lived certs (inc. ACME-STAR, Delegated Credentials, and notAfter)

Anything else I should cover?

#WebPKI #TLS

This entry was edited (1 month ago)