CRLite: A Scalable System for Pushing All TLS Revocations to All Browsers
James Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson
Abstract
Currently, no major browser fully checks for TLS/SSL certificate revocations. This is largely due to the fact that the deployed mechanisms for disseminating revocations (CRLs, OCSP, OCSP Stapling, CRLSet, and OneCRL) are each either incomplete, insecure, inefficient, slow to update, not private, or some combination thereof. In this paper, we present CRLite, an efficient and easily-deployable system for proactively pushing all TLS certificate revocations to browsers. CRLite servers aggregate revocation information for all known, valid TLS certificates on the web, and store them in a space-efficient filter cascade data structure. Browsers periodically download and use this data to check for revocations of observed certificates in realtime. CRLite does not require any additional trust beyond the existing PKI, and it allows clients to adopt a fail-closed security posture even in the face of network errors or attacks that make revocation information temporarily unavailable. We present a prototype of CRLite that processes TLS certificates gathered by Rapid7, the University of Michigan, and Google's Certificate Transparency on the server-side, with a Firefox extension on the client-side. Comparing CRLite to an idealized browser that performs correct CRL/OCSP checking, we show that CRLite reduces latency and eliminates privacy concerns. Moreover, CRLite has low bandwidth costs: it can represent all certificates with an initial download of 10 MB (less than 1 byte per revocation) followed by daily updates of 580 KB on average. Taken together, our results demonstrate that complete TLS/SSL revocation checking is within reach for all clients. Recent measurement studies demonstrate that revocation is prevalent in the web's PKI [49] . More than 99% of valid certificates available on the web contain a reachable CRL URL, while 95% include a reachable OCSP responder. Liu et al. observe that 8% of all valid certificates are revoked (6% if we focus just on valid EV certificates) [49] , with the bulk of these revocations occurring due to Heartbleed [76], [19] .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers19
- Let's Encrypt: An Automated Certificate Authority to Encrypt the Entire WebJosh Aas, Richard Barnes, Benton Case, Zakir Durumeric et al.CCS 2019 · 138 citations
- Private Blocklist Lookups with ChecklistDmitry Kogan, Henry Corrigan-GibbsUSENIX Security 2021 · 104 citations
- Cloud Strife: Mitigating the Security Risks of Domain-Validated CertificatesKevin Borgolte, Tobias Fiebig, Shuang Hao, Christopher Kruegel et al.NDSS 2018 · 63 citations
- Vacuum Filters: More Space-Efficient and Faster Replacement for Bloom and Cuckoo FiltersMinmei Wang, Mingxun Zhou, Shouqian Shi, Chen QianVLDB 2020 · 58 citations
- The ties that un-bind: decoupling IP from web services and sockets for robust addressing agility at CDN-scaleMarwan Fayed, Lorenz Bauer, Vasileios Giotsas, Sami Kerola et al.SIGCOMM 2021 · 23 citations
Builds on4
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky et al.S&P 2016 · 285 citations
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin et al.CCS 2016 · 89 citations
- Cinderella: Turning Shabby X.509 Certificates into Elegant Anonymous Credentials with the Magic of Verifiable ComputationAntoine Delignat-Lavaud, Cédric Fournet, Markulf Kohlweiss, Bryan ParnoS&P 2016 · 83 citations
- Transparency Overlays and ApplicationsMelissa Chase, Sarah MeiklejohnCCS 2016 · 58 citations
Related papers
- Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and PracticeJohn M. SchanckS&P 2025
- Does Certificate Transparency Break the Web? Measuring Adoption and Error RateEmily Stark, Ryan Sleevi, Rijad Muminovic, Devon O'Brien et al.S&P 2019 · 44 citations
- AccuRevoke: Enhancing Certificate Revocation with Distributed Cryptographic AccumulatorsMunshi Rejwan Ala Muid, Taejoong Chung, Thang HoangS&P 2025
- CTng: Secure Certificate and Revocation TransparencyJie Kong, James Damon, Hemi Leibowitz, Ewa Syta et al.NDSS 2026 · 5 citations
- Reliable and Decentralized Certificate Revocation via DNS: The Case for RevDNSTaejoong Chung, Dave Levin, Protick BhowmickSIGCOMM 2025 · 2 citations
