Re: Google about to fix the CRL download mechanism in Chrome

2012-02-09 Thread Ondrej Mikle
On 02/09/2012 01:20 AM, Brian Smith wrote: > I am also concerned about the filtering based on reason codes. Is it > realistic to expect that every site that has a key compromise to publicly > state that fact? Isn't it pretty likely that after a server's EE certificate > has been revoked, that pe

Re: Google about to fix the CRL download mechanism in Chrome

2012-02-09 Thread Rob Stradling
On 09/02/12 13:10, Gervase Markham wrote: On 09/02/12 12:54, Rob Stradling wrote: We've calculated that there are currently ~53,000 revoked Server Authentication certs that were issued by Comodo's CA systems, each with a serial number of 16 bytes (+ a leading zero byte if required to ensure it's

Re: Google about to fix the CRL download mechanism in Chrome

2012-02-09 Thread Gervase Markham
On 09/02/12 12:54, Rob Stradling wrote: We've calculated that there are currently ~53,000 revoked Server Authentication certs that were issued by Comodo's CA systems, each with a serial number of 16 bytes (+ a leading zero byte if required to ensure it's not treated as a negative number). That ad

Re: Google about to fix the CRL download mechanism in Chrome

2012-02-09 Thread Rob Stradling
FYI, Adam Langley told me "The hope is that everything is <100KB". I asked him if I could share that figure here and he just replied "No problem. It's not a strict limit that we set and we'll have to see how well we do". We've calculated that there are currently ~53,000 revoked Server Authent