> Beginning October 1, you will be able to just download the CRLs
Correction: Apple and Mozilla will be able to just download the CRLs. Not me. The link in the post SPECIFICALLY says us common plebes don't get that right.
If you think it's because the URLs will be disclosed in the CCADB, note that the contents of the CCADB are published here: https://www.ccadb.org/resources
I was pretty sure this section meant what I said but maybe you can get them from that database without being a BigCo?:
“Our new CRL URLs will be disclosed only in CCADB, so that the Apple and Mozilla root programs can consume them without exposing them to potentially large download traffic from the rest of the internet at large.”
I assumed what they meant is that the database is publicly available but that browser implementations won't be directly pulling CRLs. Instead the browser providers pull the CRLs and create a compressed version that their browser users download.
In the same way that you can technically query the DNS root servers yourself but you don't tend to do that because your computer will query a more downstream DNS server.
Correction: Apple and Mozilla will be able to just download the CRLs. Not me. The link in the post SPECIFICALLY says us common plebes don't get that right.