4 ms·
It's because CRLs/OCSP sucks so now short expiration is rolling out.
by kxxt 1y ago
It's because CRLs/OCSP sucks so now short expiration is rolling out.
- ozim 1y agoCRL doesn’t suck it is just not easy problem on web scale. But seems like there is feasible solution: https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/ https://hacks.mozilla.org/2025/08/crlite-fast-private-and-co...