Reliable and Decentralized Certificate Revocation via DNS: The Case for RevDNS
Taejoong Chung, Dave Levin, Protick Bhowmick
Abstract
The Online Certificate Status Protocol's long slide-after 25 years of soft-fail rules, privacy leakage, and shaky infrastructure-exposes a deeper failure in web-PKI revocation. Certificate Authorities increasingly route OCSP traffic through CDNs for speed, yet this recentralizes trust: our measurements show Akamai serves 62 percent of all revocation responses, creating single points of failure and betraying PKI's decentralized ideals.
We present RevDNS, a DNS-based revocation scheme that drops CDN dependence while preserving real-time guarantees. Revoked serial numbers live in DNSSEC-signed TXT records; NSEC proofs allow aggressive negative caching, so recursive resolvers answer 99.8 percent of checks without bothering a CA. From 1.1 billion certificates and 5 million revocations, we find a large CA such as Let's Encrypt can publish data for 612 million certificates in a 345 MB zone, with resolvers shouldering nearly every lookup.
Because answers piggyback on ordinary DNS lookups, RevDNS adds no latency and discloses no more about users than standard DNS traffic. By keeping revocation authority with CAs and avoiding fragile hacks like short-lived certificates, RevDNS delivers a durable, decentralized path for TLS revocation-one that finally aligns operational practicality with the web's security ambitions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on3
- A Longitudinal, End-to-End View of the DNSSEC EcosystemTaejoong Chung, Roland van Rijswijk-Deij, Balakrishnan Chandrasekaran, David R. Choffnes et al.USENIX Security 2017 · 125 citations
- Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and PracticeJohn M. SchanckS&P 2025
- Let's Revoke: Scalable Global Certificate RevocationTrevor Smith, Luke Dickenson, Kent E. SeamonsNDSS 2020
Related papers
- AccuRevoke: Enhancing Certificate Revocation with Distributed Cryptographic AccumulatorsMunshi Rejwan Ala Muid, Taejoong Chung, Thang HoangS&P 2025
- Experiences Deploying Multi-Vantage-Point Domain Validation at Let's EncryptHenry Birge-Lee, Liang Wang, Daniel McCarney, Roland Shoemaker et al.USENIX Security 2021 · 23 citations
- CRLite: A Scalable System for Pushing All TLS Revocations to All BrowsersJames Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs et al.S&P 2017 · 105 citations
- Akamai DNS: Providing Authoritative Answers to the World's QueriesKyle Schomp, Onkar Bhardwaj, Eymen Kurdoglu, Mashooq Muhaimen et al.SIGCOMM 2020 · 38 citations
- Let's Downgrade Let's EncryptTianxiang Dai, Haya Schulmann, Michael WaidnerCCS 2021 · 16 citations
