
Jump to: navigation, search

CA/Revocation Checking in Firefox

147 bytes removed, 21:55, 14 August 2019
deleted sentence that wasn't entirely correct, and was unnecessary.
Like OCSP must-staple, short-lived certificates are another fast-path option for websites, since a supporting browser will skip all revocation checks. Using short-lived certificates instead of a must-staple extension also removes the need to send an OCSP response in the handshake.
Unfortunately, the adoption of short-lived certificates has been hampered by current CA/Browser Forum rules requiring OCSP for all certificates.
Firefox does not perform any form of revocation checking for certificates with a validity period of less than 10 days. That period is configurable via the security.pki.cert_short_lifetime_in_days preference.
Confirm, administrator

Navigation menu