Discussion on ATS checking origin certificate revocation status
Open
New Feature
Stale
TLS
- Dominant language
- C++
- Stars
- 2k
- Forks
- 874
- Avg merge
- 6d 15h
- Merged PRs (30d)
- 46
Description
This came up as a result of https://www.digicert.com/support/certificate-revocation-incident
Does ATS check revocation status of origin certificates? If not, should it be a configuration setting to do so?
Regarding which method to use, this recent post from Let's Encrypt indicates OCSP (not stapling) on the way out and CRLs are in fashion again: https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html
Contributor guide
Assessment
This issue has not been assessed yet.