Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I meant programmatically. The admin can also text me every time he revokes a certificate, but the point of CRL/OCSP/... is to not do that.


Everything I described can be done programmatically. I've written the code to do it.

But anyways, as mcpherrinm reminded me, certificates will still have the CRL Distribution Point extension so you can forget what I said about the CCADB and just do what the RFCs say.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: