HomeUpdatesFirefox 37 with certificate revocation mechanism feature

Firefox 37 with certificate revocation mechanism functionality

The next stable version of Mozilla Firefox will no longer require an update to revoke a digital certificate when an incident requires it, thanks to the implementation of a new certificate revocation mechanism called OneCRL.

Firefox 37 Certificate Revocation Mechanism
This feature will replace OCSP (online certificate status protocol) and push an updated revocation list to the browser without doing a live check, thus significantly improving the response time for dealing with a bad certificate issue.

OneCRL is designed as part of the blocklist, which is being expanded to include digital certificates. Currently, only intermediate certificates are covered. These act as a substitute for the root cert to maintain the chain of trust. Another factor considered for this decision is keeping the blocklist smaller in size.

In a blog post published on Tuesday, Mozilla says that besides the immediate response, this development also reduces the cost involved in releasing a new version of the browser and its download by users.

Furthermore, the functionality of the feature in Firefox 37 is just the beginning, as improvements will follow, with automating the collection of recall data being one of the goals.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS