Firefox 37 To Check Security Certificates Via Blocklist

0
452

An anonymous reader writes The next version of Firefox will roll out a ‘pushed’ blocklist of revoked intermediate security certificates, in an effort to avoid using ‘live’ Online Certificate Status Protocol (OCSP) checks. The ‘OneCRL’ feature is similar to Google Chrome’s CRLSet, but like that older offering, is limited to intermediate certificates, due to size restrictions in the browser. OneCRL will permit non-live verification on EV certificates, trading off currency for speed. Chrome pushes its trawled list of CA revocations every few hours, and Firefox seems set to follow that method and frequency. Both Firefox and Chrome developers admit that OCSP stapling would be the better solution, but it is currently only supported in 9% of TLS certificates. Read more of this story at Slashdot.

Visit link:
Firefox 37 To Check Security Certificates Via Blocklist

LEAVE A REPLY

Please enter your comment!
Please enter your name here

*

This site uses Akismet to reduce spam. Learn how your comment data is processed.