Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Beginning October 1, you will be able to just download the CRLs

Correction: Apple and Mozilla will be able to just download the CRLs. Not me. The link in the post SPECIFICALLY says us common plebes don't get that right.



Where does the post say that?

If you think it's because the URLs will be disclosed in the CCADB, note that the contents of the CCADB are published here: https://www.ccadb.org/resources

Specifically, the CRL URLs can be found in this CSV file: http://ccadb-public.secure.force.com/ccadb/AllCertificateRec...


I was pretty sure this section meant what I said but maybe you can get them from that database without being a BigCo?:

“Our new CRL URLs will be disclosed only in CCADB, so that the Apple and Mozilla root programs can consume them without exposing them to potentially large download traffic from the rest of the internet at large.”


I assumed what they meant is that the database is publicly available but that browser implementations won't be directly pulling CRLs. Instead the browser providers pull the CRLs and create a compressed version that their browser users download.

In the same way that you can technically query the DNS root servers yourself but you don't tend to do that because your computer will query a more downstream DNS server.


Yes, that's exactly what it means.


I have a cron job that pulls that CSV file once a day. I assure you I am not a BigCo.


I was wrong, thanks for correcting me :)


"The connection has timed out. An error occurred during a connection to ccadb-public.secure.force.com."


Works for me, though the time to first byte is currently rather long.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: