An analysis of CRL sizes from various CAs
chasersystems.com
An analysis of CRL sizes from various CAs
1–5 of 5 posts
Re: An analysis of CRL sizes from various CAs
#2Data is on CRL availability, number of entries, expiry & refresh times, etc. from various x509 leaf server SSL certificates.
Re: An analysis of CRL sizes from various CAs
#3• Google's CRLs from the same intermediate CA (same public key) have different URLs and different content when pulled from different hosts (google.com, youtube.com).
• DigiCert has sharded according to 'assurance' class, algorithm, year and acquisition's name.
• Sectigo also has sharded according to 'assurance' class [1].
• GlobalSign has sharded by the yearly quarter presumably.
• HTTP Cache-Control maxage (or s-maxage), 'Expires' and 'Next Update' within the CRL file are not in sync.
• Some CAs other than Let's Encrypt also do not publish CRL URLs in the leaf certificates.
[1] https://www.sectigo.com/knowledge-base/detail/Sectigo-Interm...
Re: An analysis of CRL sizes from various CAs
#4Re: An analysis of CRL sizes from various CAs
#5What analysis was done or are we just talking about the data gathering?