Definition · TLS & Certificates
What is Certificate Revocation?
A TLS certificate is valid until its expiry date unless something withdraws it earlier. Revocation is that withdrawal: the issuing certificate authority records the certificate’s serial number as no longer trustworthy, typically because the private key was exposed, the certificate was issued in error, the domain changed hands, or the subscriber requested it.
How clients are meant to find out
- Certificate Revocation Lists (CRLs) — a signed list of revoked serial numbers published by the CA and fetched periodically.
- OCSP — a query-per-certificate protocol giving a signed status response, most usefully delivered by OCSP stapling from the server itself.
- Vendor-pushed data — browsers increasingly ship aggregated revocation information to clients out of band, so no network check is needed at connection time.
Why revocation is a weak control
Live revocation checking has never worked well. Checks add latency and leak browsing behaviour to the CA, and clients almost universally soft-fail: if the responder cannot be reached, the connection proceeds. An attacker positioned to use a stolen key is usually also positioned to block the revocation check, which is precisely the situation the check was supposed to cover. Browsers responded by stepping back from per-connection lookups in favour of pushed summaries, and Let’s Encrypt ended its OCSP service in 2025.
The practical consequence is that revocation should not be treated as a reliable kill switch. The industry’s answer is shorter certificate lifetimes: a certificate valid for weeks limits the damage from a compromised key without depending on every client checking anything. That is the reasoning behind the CA/Browser Forum’s phased reduction in maximum lifetimes, and another argument for automated issuance through ACME.
What to do after a key compromise
Revoke, but do not stop there. Rotate the key and reissue rather than reusing the same key pair, redeploy every service that used the certificate — including load balancers, mail servers and appliances that were configured once and forgotten — and check Certificate Transparency logs for anything else issued against the affected names. If the certificate was a wildcard, the exposure covers every host it covered.
Related concepts
See certificate chain, certificate pinning, CAA records and TLS and certificates.