Skip to content
TrackPodcasts
technologyDec 14, 202010:29pending

Certificates Gone Bad! Certificate Revocation Techniques Explained (CRL, OCSP, OCSP Stapling)

About this episode

When the private key of a matching public key that belong to a certificate is leaked, an attacker can intercept server hello, use their own dh parameters sign it with the stolen private key and ship it to the client effectively doing MITM. This is extremely dangerous and we have no way in the client to know a MITM has happened.

That is why a certificate sometimes has to be revoked, and in this video I’m going to discuss those revocation techniques.

0:00 How Certificate Works

3:00 Certificate Revocation List

4:10 OCSP

7:00 OCSP Stapling

Get every episode summarized

Each time The Backend Engineering Show with Hussein Nasser publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

Certificates Gone Bad! Certificate Revocation Techniques Explained (CRL, OCSP, OCSP Stapling)

The Backend Engineering Show with Hussein Nasser

0:00
10:29

More episodes

More from The Backend Engineering Show with Hussein Nasser

View all episodes →