Skip to content

wfe: Add a CRL handler and record when revocations reach the CRL - #561

Open
Preston12321 wants to merge 1 commit into
crl-signingfrom
crl-handler
Open

Preston12321 wants to merge 1 commit into
crl-signingfrom
crl-handler

Conversation

@Preston12321

@Preston12321 Preston12321 commented Sep 27, 2026 •

Copy link
Copy Markdown

Add CRLHandler, which serves a freshly signed CRL at the CA's CRL URL, and set CRLVisibleAt on revoked certificates so that revocations appear on the CRL after a random delay.

The handler isn't served yet.

Note: This change is entirely generated by Claude, but I provided significant guidance and have manually reviewed the diff

Add CRLHandler, which serves a freshly signed CRL at the CA's CRL URL,
and set CRLVisibleAt on revoked certificates so that revocations appear
on the CRL after a random delay.

The handler isn't served yet.
@Preston12321
Preston12321 added this pull request to stack #559 September 27, 2026 03:47
@Preston12321
Preston12321 marked this pull request as ready for review September 27, 2026 04:06

@aarongable aarongable left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, but see my comments on the preceding PR in the stack about getting rid of CRLVisibleAt, and instead caching the most recently-signed CRL for some period of time.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants