Published on

Chromium Revokation Check

Authors
  • Name
    Naito Oshima
    Twitter

Chromium Revokation Check

Chromium does not perform online certificate revocation checks such us OCSP and CRL by default.

Instead, Chrome users can enabled explicitly using EnableOnlineRevocationChecks policy:

Chrome Policy - EnableOnlineRevocationChecks

If enabled, Chromium does perform revocation checks using original Chromium CRLSets:

Chromium CRLSets

Chaniging Revokation Check for EV certificates

Exceptionally, in case of Extended Validation (EV) certificates, previously it does peroform revocation checks.

However, it seems that it also stopped Revokation Check for EV certificates after chromium 106.0.5249.0.

Chromium bug - #1268848 Chromium commit - a5b2b97b4396b5eff69c41f4cb05d9ae79887d06