4 ms·
Yes it does. It's just not enabled by default.
by nav1 12y ago
Yes it does. It's just not enabled by default.
- fastest963 12y agoHow many people are going to check that box under "Advanced Settings"? 0.1%?
- scrollaway 12y agoUnlikely to be that high. The 0.1% that may dig in those advanced settings is likely the same 0.1% that disabled the thing back when it was enabled by default. CRLs are worthless.
- fastest963 12y agoWorthless except when your cert key is stolen and you want to revoke the old one?
- sp332 12y agoWhat good is it to revoke one, if it still works because no one checked the revocation list?
- fastest963 12y agoThat's the whole point of me posting this...
- iancarroll 12y agoHow are they worthless?
- msherry 12y agoThey're worthless because clearly no one is using them. They may theoretically be useful, but it doesn't matter if they're never put into practice.
- iancarroll 12y agoDo you mean nobody on the CA side or the end user side? CA's suspend certificates all the time - instant e the scam site had theirs pulled a few weeks ago...
- nullc 12y agoBeyond being seldom used, they also leak usage information.
- dfc 12y agoIf you are leaking usage information with ocsp/crl checks you are also spewing out information via DNS requests.
- snogglethorpe 12y agoStill, having that setting there means you can easily tell people to turn it on...