5997 links
  • GuiGui's Show

  • Home
  • Login
  • RSS Feed
  • Tag cloud
  • Picture wall
  • Daily
Links per page: 20 50 100
page 1 / 1
  • OCSP Service Has Reached End of Life - Let's Encrypt

    Today we turned off our Online Certificate Status Protocol (OCSP) service, as announced in December of last year. […] Going forward, we will publish revocation information exclusively via Certificate Revocation Lists (CRLs).
    We ended support for OCSP primarily because it represents a considerable risk to privacy on the Internet. When someone visits a website using a browser or other software that checks for certificate revocation via OCSP, the Certificate Authority (CA) operating the OCSP responder immediately becomes aware of which website is being visited from that visitor’s particular IP address. Even when a CA intentionally does not retain this information, as is the case with Let’s Encrypt, it could accidentally be retained or CAs could be legally compelled to collect it. CRLs do not have this issue.
    […]
    For every year that we have existed, operating OCSP services has taken up considerable resources that can soon be better spent on other aspects of our operations. […] That’s more than 140,000 requests per second handled by our CDN, with 15,000 requests per second handled by our origin. […]

    \o/

    Un de mes deux griefs majeurs envers LE est donc caduque.

    31/08/2025 16:24:29 - permalink -
    - https://letsencrypt.org/2025/08/06/ocsp-service-has-reached-end-of-life
Links per page: 20 50 100
page 1 / 1
Mentions légales identiques à celles de mon blog | CC BY-SA 3.0

Shaarli - The personal, minimalist, super-fast, database free, bookmarking service by the Shaarli community