Handshake Papers
Handshake Papers
@HandshakePapers

What happens to a certificate that's stolen before it expires?

What happens to a certificate that's stolen before it expires?

If a private key leaks today but the certificate is valid for another year, how does the world find out it's no longer trustworthy? This is the revocation problem, and the honest answer is: imperfectly.

When a key is compromised, the CA revokes the certificate. Two mechanisms historically published that fact:

— CRL (Certificate Revocation List): a signed list of revoked serial numbers the client downloads. These grew to megabytes, so browsers largely abandoned live CRL checks.
— OCSP (Online Certificate Status Protocol, RFC 6960): the client asks the CA's responder "is serial X still good?" in real time.

OCSP has a notorious flaw: most browsers fail open. If the responder is slow or unreachable, the browser proceeds anyway — otherwise a CA outage would break the whole web. So a man-in-the-middle who can also block the OCSP query renders revocation useless.

The industry's verdict is striking: in 2024 Let's Encrypt announced it would stop serving OCSP entirely, citing privacy (the responder learns which sites users visit) and unreliability. The future is short certificate lifetimes plus browser-pushed revocation sets (Mozilla's CRLite, Chrome's CRLSets).

Further reading: RFC 6960 (OCSP); Let's Encrypt "Intent to End OCSP Service" (2024).

Bottom line: revocation is the weakest joint in the system. Soft-fail OCSP barely works — which is why the answer is becoming "just use very short-lived certificates."
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.