5 ms·
This is a good behavior, since it means less bytes to transfer per connection. Worst case scenario, the browser doesn't have/can't get the intermediate certs re
by bighoss97 3y ago
This is a good behavior, since it means less bytes to transfer per connection. Worst case scenario, the browser doesn't have/can't get the intermediate certs required and the connection fails.
- minaguib 3y agoI agree with the author that the non-deterministic portion of it is mildly insane. Imagine a junior admin who installs a new certificate (without the intermediate). Tests on their Chrome which happens to have cached the intermediate, validate LGTM and moves on. Meanwhile it gets deployed and some portion of the site's users don't have the intermediate certificate cached = dungeon collapse.
- woodruffw 3y agoThis doesn't really guarantee fewer bytes per connection. In the worse case, the preloaded intermediate set is still insufficient and the client has to resort to AIA chasing instead (which is both slower and leaks the client to the issuing CA). I understand this behavior from a "make the spurious user bug reports go away" perspective, but it's still pretty gnarly :-)