{"id":2981,"date":"2022-06-21T19:26:00","date_gmt":"2022-06-21T19:26:00","guid":{"rendered":"https:\/\/sectigostore.com\/blog\/?p=2981"},"modified":"2022-05-16T20:13:17","modified_gmt":"2022-05-16T20:13:17","slug":"what-is-a-crl-a-certificate-revocation-list-explained","status":"publish","type":"post","link":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/","title":{"rendered":"What Is a CRL? A Certificate Revocation List Explained"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">In 2014, Mozilla moved away from using certificate revocation lists (CRLs) to check the validity of TLS certificates with the release of Firefox 28.0. So, do CRLs still matter? Yes, they do \u2014 here\u2019s why they are still used by many certificate authorities and browsers, including Google Chrome.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Staying safe online is a big issue, and internet users are increasingly expecting to be assured that their online activity is secure. <a href=\"https:\/\/sectigostore.com\/ssl-certificates\">SSL\/TLS certificates<\/a> are a valuable tool, giving us important details about the status of websites and helping us to secure our networks and private data from the prying eyes of cybercriminals \u2013 but they become useless if they are invalid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">TLS certificates can become invalidated typically in one of two ways \u2014 <a href=\"https:\/\/sectigostore.com\/page\/what-will-happen-if-my-ssl-certificate-expires\/\">certificate expiration<\/a> and revocation. The TLS certificates can become invalidated typically in one of two ways \u2014 expiration and revocation. The certificate clearly mentions the expiration date, and browsers generally won\u2019t connect to a website with an expired certificate. But what if the certificate is revoked before its assigned expiration date? Browsers have a few different ways of dealing with this, including checking a CA\u2019s certificate revocation list (CRL), their online certificate status protocol (OCSP) responses, and the related process known as OCSP stapling.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In future articles, we\u2019ll look at OCSP and OCSP stapling more in depth. But for now, we\u2019ll focus on learning and exploring everything \u201cCRL\u201d in this article.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is a Certificate Revocation List? CRLs Defined and Explained<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A certificate revocation list is an indelible list of websites that have been revoked by the certificate authorities (CAs) that issued them prior to their assigned expiration dates. Basically, it\u2019s a list of certificates that\u2019s continually updated to warn browsers and operating systems that something is wrong and that they should avoid visiting those websites because they\u2019re not secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once a certificate is added to the list, it can never be removed. The whole point is for the list to serve as a permanent record.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s take a quick peek at what a CRL looks like. We\u2019ll use Sectigo\u2019s certificate revocation list (CRL) as an example:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"949\" height=\"612\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-crl-example.jpg\" alt=\"A side-by-side graphic that features two screenshots of information from Sectigo's certificate revocation list. \" class=\"wp-image-2983\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-crl-example.jpg 949w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-crl-example-300x193.jpg 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-crl-example-560x361.jpg 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-crl-example-940x606.jpg 940w\" sizes=\"auto, (max-width: 949px) 100vw, 949px\" \/><figcaption><em>Two side-by-side screenshots that showcase the Sectigo certificate revocation list information that\u2019s publicly available.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Still feeling a bit unclear on all of this? Think of a certificate revocation list as something akin to U.S. <a href=\"https:\/\/www.recalls.gov\/\">recalls.gov website<\/a>. This site contains lists of various categories of products that have been recalled by manufacturers due to safety, health, or other critical concerns. Basically, this list informs you that there\u2019s something wrong with specific items and that you should avoid using them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Like products listed on the government recall list, websites on the CA\u2019s list of revoked certificates are not trustworthy. Certificate authorities release their CRLs containing details about revoked certificates at regular intervals, which vary based on each individual CA\u2019s policies. Once a certificate is revoked, it will always remain on the CRL.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Based on the information contained in the CRL, if a website certificate is valid, the browser will allow the connection. If the certificate is revoked, the browser will show a warning similar to this:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"593\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-warning-message-example-1024x593.png\" alt=\"A screenshot of a revoked certificate warning message that browsers display to users when they visit sites that are using one or more certificates on a certificate revocation list (CRL).\" class=\"wp-image-2984\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-warning-message-example-1024x593.png 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-warning-message-example-300x174.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-warning-message-example-560x324.png 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-warning-message-example-1536x890.png 1536w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-warning-message-example-2048x1186.png 2048w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/revoked-certificate-warning-message-example-940x544.png 940w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>A screenshot of the browser warning after attempting to connect a website with a revoked certificate.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What Information Does a CRL Contain?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A CRL can contain a lot of information:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>CRL issue date and date of next update<\/li><li>Certificate issuer names<\/li><li>The cryptographic <a href=\"https:\/\/sectigostore.com\/blog\/what-is-a-digital-signature-and-how-does-the-digital-signature-process-work\/\">digital signature algorithm<\/a> used to digitally sign the CRL<\/li><li>The serial numbers of the revoked certificates<\/li><li>Revocation date and time<\/li><li>Reason for each certificate\u2019s revocation (optional)<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">However, most certificate revocation entries typically just include the serial number and revocation date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following screenshots show the CRL generated and published by Adobe CA. You can see that there are two boxes in the first screenshot. The first shows the basic information, the second box shows more details.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"546\" height=\"679\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/adobe-ca-revocation-list-1.png\" alt=\"A screenshot of Adobe CA's CRL information that shows issuer information.\" class=\"wp-image-2988\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/adobe-ca-revocation-list-1.png 546w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/adobe-ca-revocation-list-1-241x300.png 241w\" sizes=\"auto, (max-width: 546px) 100vw, 546px\" \/><figcaption>A screenshot of general information from the certificate revocation list (CRL) from Adobe CA.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">There are three boxes in the second screenshot. The first provides an overview of all the revoked certificates the CA has and the corresponding date and time each was revoked. If you click on a particular serial number, you will see more details for that individual certificate displaying in the second box. The third box shows additional information about the certificate or the reason why it was revoked.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/adobe-ca-revocation-list-2.png\" alt=\"A screenshot of Adobe CA's CRL information that shows certificate-specific information about a certificate that was revoked and the reason why.\" class=\"wp-image-2987\" width=\"544\" height=\"673\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/adobe-ca-revocation-list-2.png 544w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/adobe-ca-revocation-list-2-242x300.png 242w\" sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><figcaption>A screenshot detailing certificate-specific information from the Adobe CA certificate revocation list (CRL).<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Why Do TLS Certificates Get Revoked?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A CA can revoke a TLS certificate for one of several reasons and the reason is recorded in the CRL with a code. In the screenshot above, we can see that the CRL reason code is &#8216;Superseded (4).&#8217; But what are these codes and what do they mean?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s take a quick peek at the <a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc5280\">certificate revocation reason codes<\/a> listed in the IETF\u2019s RFC 5280 and what they mean:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Unspecified (0)<\/strong> \u2014 Any other reason.<\/li><li><strong>KeyCompromise (1)<\/strong> \u2014 A private key is compromised.<\/li><li><strong>CACompromise (2)<\/strong> \u2014 The CA is compromised.<\/li><li><strong>AffiliationChanged (3)<\/strong> \u2014 The certificate owner is no longer with the organization.<\/li><li><strong>Superseded (4)<\/strong> \u2014 Another certificate supersedes the present certificate.<\/li><li><strong>CessationOfOperation (5)<\/strong> \u2014 The organization has ceased normal operations and the certificate has been replaced.<\/li><li><strong>CertificateHold (6)<\/strong> \u2014 If the certificate has been revoked temporarily.<\/li><li><strong>RemoveFromCRL (8)<\/strong> \u2013 A CA has been removed from the network.<\/li><li><strong>PrivilegeWithdrawn (9)<\/strong> \u2013 The privileges contained within the certificate have been withdrawn.<\/li><li><strong>AACompromise (10)<\/strong> \u2013 The <a href=\"https:\/\/www.cloudradius.com\/a-complete-guide-to-radius-servers\/\">RADIUS server<\/a> is compromised so associated certificates cannot be trusted.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note: <\/strong>Did you notice that there\u2019s no number seven on the list above? Good catch. RFC 5280 doesn\u2019t specify why the number seven isn\u2019t used. All we know is that it wasn\u2019t included.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How Does CRL Verification Work?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CRL verification is the simplest way to verify the revocation status of TLS certificates. The figure below explains the process:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"927\" height=\"738\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/how-a-crl-works-illustration-1.png\" alt=\"A basic illustration providing an overview of how a certificate revocation status check works using a CRL. \" class=\"wp-image-2986\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/how-a-crl-works-illustration-1.png 927w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/how-a-crl-works-illustration-1-300x239.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/how-a-crl-works-illustration-1-560x446.png 560w\" sizes=\"auto, (max-width: 927px) 100vw, 927px\" \/><figcaption>A figure showing a basic overview of what&#8217;s involved in the CRL method of certificate revocation status check.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As you can see, CRL verification is carried out by the client browser.<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>First, the browser sends a connection request to the server.<\/li><li>Then, the server sends its certificate to the client.<\/li><li>The client might have already downloaded and cached the CRL. If it hasn&#8217;t downloaded the CRL beforehand, it sends a request to the CA or the CRL issuer to get a copy of the list from its server.<\/li><li>Once the client receives the CRL, it can check the list to see if the server certificate is revoked.<\/li><li>If the client doesn&#8217;t see the certificate in the revocation list, it assumes that the certificate is valid and connects to the website.<\/li><li>If the browser finds the website certificate on the list, it means that it has been revoked and the website is no longer trustworthy. In this case, you will see a warning message (like the example you saw earlier) and the browser will end the connection.<\/li><\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Advantages of CRL Verification<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The online certificate status protocol (OCSP) is another way to verify the status of TLS certificates online. In the OCSP verification process, the status of a particular certificate is requested (whether it is good or not). With a CRL, the list of all the revoked certificates is requested and then the browser confirms that the particular site\u2019s TLS certificate is not on list (meaning, it\u2019s thought to still be valid and hasn\u2019t been revoked early).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When we compare CRL verification with OCSP, OCSP is the clear winner in terms of efficiency and security. Still, the CRL method does have a couple of things going for it:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>It is faster and more efficient than OCSP in situations where the client browser has to verify the revocation status of multiple certificates.<\/strong> The browser can download a single CRL and then compare multiple serial numbers against it. It doesn\u2019t need to send a request the status of individual certificates every time it needs to confirm.<\/li><li>It still works during network outages as the list is stored locally once downloaded. This differs from when the OCSP server is down \u2014 in this situation, the OCSP verification will fail.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Disadvantages of CRL Verification<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CRLs have several disadvantages compared to OCSP, including:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Taxing on Network Resources<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">CRL verification takes up more network resources as the browser must download the whole list of revoked certificates, then parse the list for the certificate of the site it is attempting to access.&nbsp; This process is also more time-consuming than with OCSP.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">No Real-Time Updates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Unlike OCSP, CRLs don&#8217;t offer real-time results as they are updated hourly, daily, or weekly. So, there is always a chance that a CRL could be outdated and the website it is trying to connect to has its certificate revoked since the last update.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">CRLs Require a Good CA Infrastructure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If the certificate authority that issues the certificate revocation list doesn\u2019t have a strong, reliable infrastructure, then you\u2019re going to run into trouble. If the CA experiences a lot of downtime and other availability-related issues, it makes it hard to get a hold of the CRL. However, the same can also be said about the OCSP server responses as well.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(This is where OCSP stapling can help \u2014 but that\u2019s a whole other topic that we aren\u2019t going to get into here. Be sure to check back over the next few weeks for our upcoming article on OCSP stapling.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Check a Certificate\u2019s Revocation Status<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many sites offer free tools to check the revocation status of websites.<a href=\"https:\/\/certificate.revocationcheck.com\/\"> Let&#8217;s see what happens if we try it for SectigoStore.com using a tool on<\/a> <a href=\"https:\/\/certificate.revocationcheck.com\/\">certificate.revocationcheck.com<\/a>:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1025\" height=\"571\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/sectigostore-certificate-revocation-status-check-example.png\" alt=\"A screenshot of a certificate revocation status check using certificate.revoccationcheck.com. \" class=\"wp-image-2989\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/sectigostore-certificate-revocation-status-check-example.png 1025w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/sectigostore-certificate-revocation-status-check-example-300x167.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/sectigostore-certificate-revocation-status-check-example-560x312.png 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/05\/sectigostore-certificate-revocation-status-check-example-940x524.png 940w\" sizes=\"auto, (max-width: 1025px) 100vw, 1025px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As you can see, the certificate is valid. This particular CRL is updated once a week by the certificate\u2019s issuing CA (Sectigo) and lists 1,295 revoked certificates (at the time this article was written). Does this sound like a high number? Just remember that this list is a permanent list, so it\u2019s no surprise that a CA that\u2019s been around since 1998 would have revoked certificates.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Image caption: A screenshot of the certificate revocation list information for Sectigo.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final Thoughts on Certificate Revocation Lists or CRLs<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A certificate revocation list contains information about all the websites with certificated revoked by the CA before their expiration date. The CA generates and issues the CRLs at intervals from once per hour to once a week. CRLs have played an important role in keeping us secure online since their introduction, but due to their cumbersome nature and the issues we mentioned earlier, the internet community is moving towards OCSP and OCSP stapling.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In 2014, Mozilla moved away from using certificate revocation lists (CRLs) to check the validity of TLS certificates with the release of Firefox 28.0. So, do CRLs still matter? Yes,&#8230;<\/p>\n","protected":false},"author":19,"featured_media":2995,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[1],"tags":[256,257],"class_list":["post-2981","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-web-security","tag-certificate-revocation-list","tag-crl","post-with-tags"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What Is a CRL? A Certificate Revocation List Explained - InfoSec Insights<\/title>\n<meta name=\"description\" content=\"A certificate revocation list (CRL) is a CA&#039;s way of informing browsers about certificates have been revoked prior to their expiration dates.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What Is a CRL? A Certificate Revocation List Explained - InfoSec Insights\" \/>\n<meta property=\"og:description\" content=\"A certificate revocation list (CRL) is a CA&#039;s way of informing browsers about certificates have been revoked prior to their expiration dates.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/\" \/>\n<meta property=\"og:site_name\" content=\"InfoSec Insights\" \/>\n<meta property=\"article:published_time\" content=\"2022-06-21T19:26:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/06\/what-is-a-crl-certificate-revocation-list-feature.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Megha Thakkar\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Megha Thakkar\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/\"},\"author\":{\"name\":\"Megha Thakkar\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/77f01ec498571464bae513fa5bfd42da\"},\"headline\":\"What Is a CRL? A Certificate Revocation List Explained\",\"datePublished\":\"2022-06-21T19:26:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/\"},\"wordCount\":1763,\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/what-is-a-crl-certificate-revocation-list-feature.jpg\",\"keywords\":[\"certificate revocation list\",\"CRL\"],\"articleSection\":[\"Web Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/\",\"name\":\"What Is a CRL? A Certificate Revocation List Explained - InfoSec Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/what-is-a-crl-certificate-revocation-list-feature.jpg\",\"datePublished\":\"2022-06-21T19:26:00+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/77f01ec498571464bae513fa5bfd42da\"},\"description\":\"A certificate revocation list (CRL) is a CA's way of informing browsers about certificates have been revoked prior to their expiration dates.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/what-is-a-crl-certificate-revocation-list-feature.jpg\",\"contentUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/what-is-a-crl-certificate-revocation-list-feature.jpg\",\"width\":1600,\"height\":1000,\"caption\":\"A screenshot of a certificate revocation list warning message on a computer screen\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-crl-a-certificate-revocation-list-explained\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What Is a CRL? A Certificate Revocation List Explained\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\",\"name\":\"InfoSec Insights\",\"description\":\"SectigoStore.com Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/77f01ec498571464bae513fa5bfd42da\",\"name\":\"Megha Thakkar\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/390ac6e8c0915150ea845acfc11db159571a2dc74d5745edc8edacec9f996bce?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/390ac6e8c0915150ea845acfc11db159571a2dc74d5745edc8edacec9f996bce?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/390ac6e8c0915150ea845acfc11db159571a2dc74d5745edc8edacec9f996bce?s=96&d=mm&r=g\",\"caption\":\"Megha Thakkar\"},\"description\":\"Megha can usually be found reading, writing, or watching documentaries, guaranteed to bore her family. She is a techno-freak with interests ranging from cooking to travel. A regular contributor to various web security blogs, she has earned her diploma in network-centric computing. Being a mother has taught her to speak less and write more (coz who listens to moms, right?).\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What Is a CRL? A Certificate Revocation List Explained - InfoSec Insights","description":"A certificate revocation list (CRL) is a CA's way of informing browsers about certificates have been revoked prior to their expiration dates.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/","og_locale":"en_US","og_type":"article","og_title":"What Is a CRL? A Certificate Revocation List Explained - InfoSec Insights","og_description":"A certificate revocation list (CRL) is a CA's way of informing browsers about certificates have been revoked prior to their expiration dates.","og_url":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/","og_site_name":"InfoSec Insights","article_published_time":"2022-06-21T19:26:00+00:00","og_image":[{"width":1600,"height":1000,"url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/06\/what-is-a-crl-certificate-revocation-list-feature.jpg","type":"image\/jpeg"}],"author":"Megha Thakkar","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Megha Thakkar","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/#article","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/"},"author":{"name":"Megha Thakkar","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/77f01ec498571464bae513fa5bfd42da"},"headline":"What Is a CRL? A Certificate Revocation List Explained","datePublished":"2022-06-21T19:26:00+00:00","mainEntityOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/"},"wordCount":1763,"image":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/06\/what-is-a-crl-certificate-revocation-list-feature.jpg","keywords":["certificate revocation list","CRL"],"articleSection":["Web Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/","url":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/","name":"What Is a CRL? A Certificate Revocation List Explained - InfoSec Insights","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/#primaryimage"},"image":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/06\/what-is-a-crl-certificate-revocation-list-feature.jpg","datePublished":"2022-06-21T19:26:00+00:00","author":{"@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/77f01ec498571464bae513fa5bfd42da"},"description":"A certificate revocation list (CRL) is a CA's way of informing browsers about certificates have been revoked prior to their expiration dates.","breadcrumb":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/#primaryimage","url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/06\/what-is-a-crl-certificate-revocation-list-feature.jpg","contentUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2022\/06\/what-is-a-crl-certificate-revocation-list-feature.jpg","width":1600,"height":1000,"caption":"A screenshot of a certificate revocation list warning message on a computer screen"},{"@type":"BreadcrumbList","@id":"https:\/\/sectigostore.com\/blog\/what-is-a-crl-a-certificate-revocation-list-explained\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sectigostore.com\/blog\/"},{"@type":"ListItem","position":2,"name":"What Is a CRL? A Certificate Revocation List Explained"}]},{"@type":"WebSite","@id":"https:\/\/sectigostore.com\/blog\/#website","url":"https:\/\/sectigostore.com\/blog\/","name":"InfoSec Insights","description":"SectigoStore.com Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sectigostore.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/77f01ec498571464bae513fa5bfd42da","name":"Megha Thakkar","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/390ac6e8c0915150ea845acfc11db159571a2dc74d5745edc8edacec9f996bce?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/390ac6e8c0915150ea845acfc11db159571a2dc74d5745edc8edacec9f996bce?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/390ac6e8c0915150ea845acfc11db159571a2dc74d5745edc8edacec9f996bce?s=96&d=mm&r=g","caption":"Megha Thakkar"},"description":"Megha can usually be found reading, writing, or watching documentaries, guaranteed to bore her family. She is a techno-freak with interests ranging from cooking to travel. A regular contributor to various web security blogs, she has earned her diploma in network-centric computing. Being a mother has taught her to speak less and write more (coz who listens to moms, right?)."}]}},"_links":{"self":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/2981","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/comments?post=2981"}],"version-history":[{"count":0,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/2981\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media\/2995"}],"wp:attachment":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media?parent=2981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/categories?post=2981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/tags?post=2981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}