DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Revocation of X.509 certificates

Quality: 9/10 Relevance: 9/10

Summary

Geoff Huston explains X.509 certificate revocation, covering CRLs, OCSP, and stapled OCSP, and discusses their real-world limitations. Using a Lets Encrypt revoked certificate example, the article highlights browser gaps, privacy concerns, and signaling challenges for timely trust updates. It also explores potential directions such as shorter certificate lifetimes and DNS/DANE based approaches as alternatives to traditional revocation.

🚀 Service construit par Johan Denoyer