Skip to content

Discussion on ATS checking origin certificate revocation status #11629

@djcarlin

Description

@djcarlin

This came up as a result of https://www.digicert.com/support/certificate-revocation-incident

Does ATS check revocation status of origin certificates? If not, should it be a configuration setting to do so?

Regarding which method to use, this recent post from Let's Encrypt indicates OCSP (not stapling) on the way out and CRLs are in fashion again: https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions