Question on Firefox's Certificate Revocation Checking

861 views
Skip to first unread message

bruce lee

unread,
Feb 5, 2024, 11:49:11 AM2/5/24
to dev-pl...@mozilla.org

Dear Firefox developers,

I would like to understand how Firefox checks for certificate revocation status when validating SSL certificates. Could you please explain what method Firefox uses to verify whether a certificate has been revoked? Proper revocation checking is an important security practice, so I would appreciate any details you can provide on how this works in Firefox.

Thank you in advance for your assistance. Please let me know if you need any clarification from me.

John Schanck

unread,
Feb 5, 2024, 12:44:04 PM2/5/24
to bruce lee, dev-pl...@mozilla.org
The information in
https://wiki.mozilla.org/CA/Revocation_Checking_in_Firefox is largely
up to date. Although we've moved beyond "preparing to test" CRLite and
we are now actively evaluating its performance with a subset of our
release population.

John
> --
> You received this message because you are subscribed to the Google Groups "dev-pl...@mozilla.org" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to dev-platform...@mozilla.org.
> To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-platform/aec15cfd-c9e9-4acf-8a4d-e31fbe4aea90n%40mozilla.org.

Dana Keeler

unread,
Feb 5, 2024, 12:47:54 PM2/5/24
to John Schanck, bruce lee, dev-pl...@mozilla.org
Incidentally, the section on revocation checking for extended validation certificates is out of date - I'm working on getting that fixed (intermediates are no longer required to have OCSP information for EV, so Firefox skips checking for it).

bruce lee

unread,
Aug 12, 2024, 5:55:47 AM8/12/24
to dev-pl...@mozilla.org, dke...@mozilla.com, bruce lee, dev-pl...@mozilla.org, jsch...@mozilla.com
As of today, how is the revocation status being checked?

Dana Keeler

unread,
Aug 12, 2024, 2:40:40 PM8/12/24
to bruce lee, dev-pl...@mozilla.org
The information in https://wiki.mozilla.org/CA/Revocation_Checking_in_Firefox is largely up to date.
CRLite is still in development.

Dana
Reply all
Reply to author
Forward
0 new messages