Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A unique per certificate CRL might work in theory. Theory is not the same as practice


Per-certificate CRLs are possible, though have about the same privacy problems as OCSP (without any of the possible advantages like OCSP pinning)


Internal / private certificate distribution monitoring, but yes privacy beyond that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: