Answer the question
In order to leave comments, you need to log in
CRL, what and how?
Hey habr!
In connection with this topic, a question arose.
Where should the browser get the list of revoked certificates? It is clear that the CRL is updated and made available to the public by certificate authorities (for example, verisign ), but how does the browser (or not the browser?) know the URL of this list.
Is the URL stored in the root certificate? Does the browser remember it separately?
Answer the question
In order to leave comments, you need to log in
Each added root certificate has (more precisely, it is provided) the ability to specify the url address at which the certification authority publishes a list of certificates revoked by this authority.
What to do with this list of revoked certificates, each client then decides for himself.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question