boulder icon indicating copy to clipboard operation
boulder copied to clipboard

Drop revocation info for short-lived certs

Open aarongable opened this issue 1 year ago • 2 comments

Add a feature flag which, if enabled and the cert has a validity period less than 7 days, results in OCSP and CRL info being omitted from the cert.

aarongable avatar Aug 20 '24 18:08 aarongable

Blocked on Microsoft root program still requiring OCSP for everything, regardless of validity period or the presence of CRLDP.

aarongable avatar Aug 27 '24 18:08 aarongable

The Microsoft Root Program no longer requires OCSP if a CRLDP is present. However, it does not include a carve-out for short-lived certs, so we cannot drop CRLDPs from 6-day certs yet.

aarongable avatar Mar 10 '25 21:03 aarongable