UK TimesUK Times
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
What's Hot
Iran protesters sent warning by Met Police with thousands set to gather in London for Al Quds Day demonstration – UK Times

Iran protesters sent warning by Met Police with thousands set to gather in London for Al Quds Day demonstration – UK Times

15 March 2026

M5 southbound within J18 before A4 access | Southbound | Broken down vehicle

15 March 2026
Young boy and his pregnant mother killed by Israeli airstrike in Gaza, hospital officials say – UK Times

Young boy and his pregnant mother killed by Israeli airstrike in Gaza, hospital officials say – UK Times

15 March 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
UK TimesUK Times
Subscribe
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
UK TimesUK Times
Home » Provisioning and managing certificates in the Web PKI | National Cyber Security Centre
News

Provisioning and managing certificates in the Web PKI | National Cyber Security Centre

By uk-times.com15 March 2026No Comments3 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

Certificate revocation is the process by which certificates can be invalidated before they naturally expire. There are several events that would warrant revocation, ranging from known or suspected private key compromise through to simply not running the domain or service any longer (and thus not needing the certificate). In order to revoke a certificate, the issuing CA adds the certificate to a publicly available list known as a Certificate Revocation List (CRL). Then, when validating a certificate, the client verifies that the certificate they are attempting to authenticate is not contained in the CRL of the issuing CA, implying that it remains valid.  

In the Web PKI, CRLs grow too large to be practical for clients to use directly, and so most browsers have innovated bespoke solutions to use in certificate chain validation. Common examples include CRLSets, which selects a subset of the CRLs to use (generally only high profile and/or CA certificates), and CRLite, which embeds the revocation information contained in the CRLs into a more compact data structure, but such solutions are not ubiquitous across all clients.

A mechanism called Online Certificate Status Protocol (OCSP) was designed to avoid end users having to obtain and store massive CRLs. In this case, the OCSP responder is responsible for obtaining the up-to-date CRL from the CA and checks the certificate status on behalf of the end user.  This service is costly to run since it needs to be highly available, resilient and scalable to ensure that OCSP provides any security benefit, and is not mandatory for CAs to implement. Additionally, there are privacy concerns with OCSP as in order to obtain revocation information, the client has to divulge the domain or service it wishes to access to the OCSP responder.  

An alternative is OCSP stapling, in which the domain or service obtains the OCSP response for its certificate and provides it to clients itself and so protects the client privacy. However, OCSP stapling is not particularly well supported in the Web PKI.  

In summary, neither CRLs nor OCSPs as they’re currently deployed provide an ideal solution to the revocation problem for the Web PKI. Despite this, in response to a revocation-worthy event, we still strongly recommend that a domain or service owner revokes this key through the CA (possibly via your certificate management automation software) and gets it added to the CRL. However, this should be done in the knowledge that it cannot be guaranteed that this revocation status will percolate through to all end users.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related News

Iran protesters sent warning by Met Police with thousands set to gather in London for Al Quds Day demonstration – UK Times

Iran protesters sent warning by Met Police with thousands set to gather in London for Al Quds Day demonstration – UK Times

15 March 2026

M5 southbound within J18 before A4 access | Southbound | Broken down vehicle

15 March 2026
Young boy and his pregnant mother killed by Israeli airstrike in Gaza, hospital officials say – UK Times

Young boy and his pregnant mother killed by Israeli airstrike in Gaza, hospital officials say – UK Times

15 March 2026

A2 eastbound between A296 and A2260 | Eastbound | Broken down vehicle

15 March 2026
F1 standings after Chinese GP race as Kimi Antonelli closes gap to George Russell – UK Times

F1 standings after Chinese GP race as Kimi Antonelli closes gap to George Russell – UK Times

15 March 2026

A19 southbound between A1027 and A139 | Southbound | Broken down vehicle

15 March 2026
Top News
Iran protesters sent warning by Met Police with thousands set to gather in London for Al Quds Day demonstration – UK Times

Iran protesters sent warning by Met Police with thousands set to gather in London for Al Quds Day demonstration – UK Times

15 March 2026

M5 southbound within J18 before A4 access | Southbound | Broken down vehicle

15 March 2026
Young boy and his pregnant mother killed by Israeli airstrike in Gaza, hospital officials say – UK Times

Young boy and his pregnant mother killed by Israeli airstrike in Gaza, hospital officials say – UK Times

15 March 2026

Subscribe to Updates

Get the latest UK news and updates directly to your inbox.

Recent Posts

  • Iran protesters sent warning by Met Police with thousands set to gather in London for Al Quds Day demonstration – UK Times
  • M5 southbound within J18 before A4 access | Southbound | Broken down vehicle
  • Young boy and his pregnant mother killed by Israeli airstrike in Gaza, hospital officials say – UK Times
  • A2 eastbound between A296 and A2260 | Eastbound | Broken down vehicle
  • Country star Jo Dee Messina says Nashville record label called her ‘too fat’

Recent Comments

No comments to show.
© 2026 UK Times. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version