Hacker News new | past | comments | ask | show | jobs | submit login

mail



Like SMTP/IMAP etc? That would make sense, though I'm not sure how much revocation checking even happens there.


OCSP stapling: free feature of TLS library, works

OCSP must-staple: free feature of TLS library, works

plain OCSP: hit & miss, depends on the client software using the TLS library correctly

CRL: no.

… that's the crux of this entire thread.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: