CA:EV Revocation Checking

From MozillaWiki
Revision as of 18:52, 29 January 2008 by Hecker (talk | contribs) (Create initial page)
Jump to navigation Jump to search

EV certificates and revocation checking

When a site presents an Extended Validation (EV) certificate to Firefox 3, the UI displayed to the user is dependent on the type and results of revocation checking in effect for that certificate. This page attempts to clarify the rules for the various possible cases. (See bug 405139 for the original motivation behind this.)

Some underlying variables affecting this:

  • whether OCSP has been disabled by the user or not
  • whether the EV certificate has an OSCP AIA extension or not
  • whether the OCSP check succeeds or not