rustls / rustls/webpki

Consider all candidate CRLs

Open
#526 2 comments 0 reactions 1 assignee View on GitHub

@cpu is already working on this.

Since Aug 21, 2026.

Dominant language
Rust
Stars
160
Forks
102
Avg merge
28m
Merged PRs (30d)
5

Description

At the moment RevocationOptions::check looks for "the" CRL. I think this should be restructured, like path building, so:

  • each authoritative CRL is attempted
  • an error for a given CRL is accumulated using the error ordering pattern established in this crate, starting with a base of Error::UnknownRevocationStatus
  • a CertRevoked determination stops search

@cpu thoughts?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.