{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,11]],"date-time":"2026-08-11T19:28:09Z","timestamp":1786476489066,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":50,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,8,11]],"date-time":"2026-08-11T00:00:00Z","timestamp":1786406400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,8,17]]},"DOI":"10.1145\/3789240.3829108","type":"proceedings-article","created":{"date-parts":[[2026,8,11]],"date-time":"2026-08-11T18:33:22Z","timestamp":1786473202000},"page":"1739-1751","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Comprehensive Revocation Checking at Scale: the Deployment of CRLite in Mozilla Firefox"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-6332-179X","authenticated-orcid":false,"given":"Nehal","family":"Fooda","sequence":"first","affiliation":[{"name":"University of Maryland, College Park, Maryland, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6279-5828","authenticated-orcid":false,"given":"James","family":"Larisch","sequence":"additional","affiliation":[{"name":"Cloudflare, Inc., San Francisco, California, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-3564-8236","authenticated-orcid":false,"given":"John","family":"Schanck","sequence":"additional","affiliation":[{"name":"Mozilla, San Francisco, California, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4323-4080","authenticated-orcid":false,"given":"Tijay","family":"Chung","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, Virginia, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4957-5131","authenticated-orcid":false,"given":"Dave","family":"Levin","sequence":"additional","affiliation":[{"name":"University of Maryland, College Park, Maryland, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5692-7062","authenticated-orcid":false,"given":"Bruce","family":"Maggs","sequence":"additional","affiliation":[{"name":"Duke University and Emerald Innovations, Cambridge, Massachusetts, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5268-004X","authenticated-orcid":false,"given":"Christo","family":"Wilson","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, Massachusetts, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,8,11]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"CA\/Browser Forum. https:\/\/cabforum.org\/."},{"key":"e_1_3_2_1_2_1","unstructured":"Certificate Transparency. https:\/\/certificate.transparency.dev\/."},{"key":"e_1_3_2_1_3_1","unstructured":"Only run CRLite on certificates with a CT SCT available December 2019. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1605273."},{"key":"e_1_3_2_1_4_1","unstructured":"Evaluate CRLite for certs older than $merge_delay December 2020. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1683525."},{"key":"e_1_3_2_1_5_1","unstructured":"SEC_ERROR_REVOKED_CERTIFICATE on hetzner.com due to security.pki.crlite_mode=2 (Nightly default) September 2020. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1667829."},{"key":"e_1_3_2_1_6_1","unstructured":"utilize crlite stashes (incremental diffs in crlite state) May 2020. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1638139."},{"key":"e_1_3_2_1_7_1","unstructured":"PSM should use the newly defined CRLite filter coverage metadata December 2021. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1747320."},{"key":"e_1_3_2_1_8_1","volume-title":"May","author":"Services Microsoft PKI","year":"2025","unstructured":"Microsoft PKI Services: Failure to Revoke in 5 Days, May 2025. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1965612."},{"key":"e_1_3_2_1_9_1","unstructured":"Revocation ain't no thang. September 2025. https:\/\/dadrian.io\/blog\/posts\/revocation-aint-no-thang\/."},{"key":"e_1_3_2_1_10_1","unstructured":"Firefox Privacy Notice January 2026. https:\/\/www.mozilla.org\/en-US\/privacy\/firefox\/?utm_source=firefox-browser&utm_medium=firefox-desktop&utm_campaign=about-dialog."},{"key":"e_1_3_2_1_11_1","unstructured":"Mozilla Data Collection Categories January 2026. https:\/\/wiki.mozilla.org\/Data_Collection#Data_Collection_Categories."},{"key":"e_1_3_2_1_12_1","unstructured":"Mozilla Data Privacy Principles January 2026. https:\/\/www.mozilla.org\/en-US\/privacy\/principles\/."},{"key":"e_1_3_2_1_13_1","unstructured":"Mozilla Privacy Policy January 2026. https:\/\/www.mozilla.org\/en-US\/privacy\/."},{"key":"e_1_3_2_1_14_1","volume-title":"We Issued Our First Six Day Cert. https:\/\/letsencrypt.org\/2025\/02\/20\/first-short-lived-cert-issued","author":"Aas Josh","year":"2025","unstructured":"Josh Aas. We Issued Our First Six Day Cert. https:\/\/letsencrypt.org\/2025\/02\/20\/first-short-lived-cert-issued, 2025."},{"key":"e_1_3_2_1_15_1","volume-title":"About upcoming limits on trusted certificates. https:\/\/support.apple.com\/en-us\/102028","year":"2020","unstructured":"Apple. About upcoming limits on trusted certificates. https:\/\/support.apple.com\/en-us\/102028, 2020."},{"key":"e_1_3_2_1_16_1","volume-title":"Certificate transparency requirements. https:\/\/support.apple.com\/en-us\/103214","author":"Apple Inc.","year":"2024","unstructured":"Apple Inc. Certificate transparency requirements. https:\/\/support.apple.com\/en-us\/103214, 2024."},{"key":"e_1_3_2_1_17_1","unstructured":"Charles Arthur. Diginotar ssl certificate hack amounts to cyberwar says expert. http:\/\/www.theguardian.com\/technology\/2011\/sep\/05\/diginotar-certificate-hack-cyberwar."},{"key":"e_1_3_2_1_18_1","volume-title":"Internet Engineering Task Force","author":"Benjamin David","year":"2026","unstructured":"David Benjamin, Devon O'Brien, Bas Westerbaan, Luke Valenta, and Filippo Valsorda. Merkle Tree Certificates. Internet-Draft draft-davidben-tls-merkle-tree-certs-10, Internet Engineering Task Force, January 2026. Work in Progress."},{"key":"e_1_3_2_1_19_1","volume-title":"ACM SIGCOMM","author":"Bhowmick Protick","year":"2025","unstructured":"Protick Bhowmick, Dave Levin, and Taejoong Chung. Reliable and Decentralized Certificate Revocation via DNS: The Case for RevDNS. In ACM SIGCOMM, September 2025."},{"key":"e_1_3_2_1_20_1","volume-title":"Ballot sc063v4: Make ocsp optional, require crls, and incentivize automation. https:\/\/cabforum.org\/2023\/07\/14\/ballot-sc063v4-make-ocsp-optional-require-crls-and-incentivize-automation\/","author":"Forum Browser","year":"2023","unstructured":"CA\/Browser Forum. Ballot sc063v4: Make ocsp optional, require crls, and incentivize automation. https:\/\/cabforum.org\/2023\/07\/14\/ballot-sc063v4-make-ocsp-optional-require-crls-and-incentivize-automation\/, 2023."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3278532.3278543"},{"key":"e_1_3_2_1_22_1","volume-title":"Vern Paxson. The Matter Of Heartbleed. In ACM Internet Measurement Conference (IMC)","author":"Durumeric Zakir","year":"2014","unstructured":"Zakir Durumeric, James Kasten, David Adrian, J. Alex Halderman, Michael Bailey, Frank Li, Nicolas Weaver, Johanna Amann, Jethro Beekman, Mathias Payer, and Vern Paxson. The Matter Of Heartbleed. In ACM Internet Measurement Conference (IMC), 2014."},{"key":"e_1_3_2_1_23_1","volume-title":"Ballot SC031: Browser Alignment. https:\/\/cabforum.org\/2020\/07\/16\/ballot-sc031-browser-alignment\/","author":"Forum CAB","year":"2020","unstructured":"CAB Forum. Ballot SC031: Browser Alignment. https:\/\/cabforum.org\/2020\/07\/16\/ballot-sc031-browser-alignment\/, 2020."},{"key":"e_1_3_2_1_24_1","volume-title":"Ballot SC081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods. https:\/\/cabforum.org\/2025\/04\/11\/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods\/","author":"Forum CAB","year":"2025","unstructured":"CAB Forum. Ballot SC081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods. https:\/\/cabforum.org\/2025\/04\/11\/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods\/, 2025."},{"key":"e_1_3_2_1_25_1","volume-title":"September","author":"Gable Aaron","year":"2022","unstructured":"Aaron Gable. A New Life for Certificate Revocation Lists, September 2022. https:\/\/letsencrypt.org\/2022\/09\/07\/new-life-for-crls."},{"key":"e_1_3_2_1_26_1","volume-title":"March","author":"Goodwin Mark","year":"2015","unstructured":"Mark Goodwin. Revoking Intermediate Certificates: Introducing OneCRL. https:\/\/blog.mozilla.org\/security\/2015\/03\/03\/revoking-intermediate-certificates-introducing-onecrl\/, March 2015."},{"key":"e_1_3_2_1_27_1","volume-title":"Chrome Certificate Transparency v3 Log List. https:\/\/www.gstatic.com\/ct\/log_list\/v3\/log_list.json","author":"Team Google Chrome CT","year":"2026","unstructured":"Google Chrome CT Team. Chrome Certificate Transparency v3 Log List. https:\/\/www.gstatic.com\/ct\/log_list\/v3\/log_list.json, 2026."},{"key":"e_1_3_2_1_28_1","volume-title":"Certificate transparency. https:\/\/chromium.googlesource.com\/chromium\/src\/+\/main\/net\/docs\/certificate-transparency.md","author":"Security Team Google Chrome","year":"2024","unstructured":"Google Chrome Security Team. Certificate transparency. https:\/\/chromium.googlesource.com\/chromium\/src\/+\/main\/net\/docs\/certificate-transparency.md, 2024."},{"key":"e_1_3_2_1_29_1","volume-title":"Chrome's plan to distrust symantec certificates. https:\/\/security.googleblog.com\/2017\/09\/chromes-plan-to-distrust-symantec.html","author":"Blog Google Security","year":"2017","unstructured":"Google Security Blog. Chrome's plan to distrust symantec certificates. https:\/\/security.googleblog.com\/2017\/09\/chromes-plan-to-distrust-symantec.html, 2017."},{"key":"e_1_3_2_1_30_1","volume-title":"Sustaining digital certificate security - entrust certificate distrust. https:\/\/security.googleblog.com\/2024\/06\/sustaining-digital-certificate-security.html","author":"Blog Google Security","year":"2024","unstructured":"Google Security Blog. Sustaining digital certificate security - entrust certificate distrust. https:\/\/security.googleblog.com\/2024\/06\/sustaining-digital-certificate-security.html, 2024."},{"key":"e_1_3_2_1_31_1","volume-title":"Real World Crypto (RWC)","author":"Hamburg Mike","year":"2022","unstructured":"Mike Hamburg. Improved CRL compression with structured linear functions. Real World Crypto (RWC), 2022."},{"key":"e_1_3_2_1_32_1","volume-title":"July","author":"Helme Scott","year":"2017","unstructured":"Scott Helme. Revocation is broken, July 2017. https:\/\/scotthelme.co.uk\/revocation-is-broken\/."},{"key":"e_1_3_2_1_33_1","unstructured":"J.C. Jones. Introducing CRLite: All of the Web PKI's revocations compressed. https:\/\/blog.mozilla.org\/security\/2020\/01\/09\/crlite-part-1-all-web-pki-revocations-compressed\/."},{"key":"e_1_3_2_1_34_1","volume-title":"March","author":"Langley Adam","year":"2011","unstructured":"Adam Langley. Revocation doesn't work, March 2011. https:\/\/www.imperialviolet.org\/2011\/03\/18\/revocation.html."},{"key":"e_1_3_2_1_35_1","volume-title":"February","author":"Langley Adam","year":"2012","unstructured":"Adam Langley. Revocation Checking And Chrome's CRL, February 2012. https:\/\/www.imperialviolet.org\/2012\/02\/05\/crlsets.html."},{"key":"e_1_3_2_1_36_1","volume-title":"April","author":"Langley Adam","year":"2014","unstructured":"Adam Langley. Revocation Still Doesn't Work, April 2014. https:\/\/www.imperialviolet.org\/2014\/04\/29\/revocationagain.html."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.17"},{"key":"e_1_3_2_1_38_1","volume-title":"Technical report","author":"Encrypt Let's","year":"2020","unstructured":"Let's Encrypt. 2020.02.29 caa rechecking bug. Technical report, 2020."},{"key":"e_1_3_2_1_39_1","volume-title":"Ending ocsp support. https:\/\/letsencrypt.org\/2024\/12\/05\/ending-ocsp\/","author":"Encrypt Let's","year":"2024","unstructured":"Let's Encrypt. Ending ocsp support. https:\/\/letsencrypt.org\/2024\/12\/05\/ending-ocsp\/, 2024."},{"key":"e_1_3_2_1_40_1","volume-title":"6-day and ip address certificates are generally available. https:\/\/letsencrypt.org\/2026\/01\/15\/6day-and-ip-general-availability","author":"Encrypt Let's","year":"2026","unstructured":"Let's Encrypt. 6-day and ip address certificates are generally available. https:\/\/letsencrypt.org\/2026\/01\/15\/6day-and-ip-general-availability, 2026."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2815675.2815685"},{"key":"e_1_3_2_1_42_1","volume-title":"October","author":"Lynch Vincent","year":"2016","unstructured":"Vincent Lynch. GlobalSign Certificate Problems Accidentally Block Sites. Hashed Out by The SSL Store, October 2016. Industry analysis of the 2016 GlobalSign revocation error and its impact on OCSP and CDN caching."},{"key":"e_1_3_2_1_43_1","volume-title":"https:\/\/www.firefox.com\/en-US\/firefox\/135.0\/releasenotes\/","author":"Firefox","year":"2025","unstructured":"Mozilla. Firefox 135.0 release notes. https:\/\/www.firefox.com\/en-US\/firefox\/135.0\/releasenotes\/, 2025."},{"key":"e_1_3_2_1_44_1","volume-title":"rust-query-crlite microbenchmark extension. https:\/\/github.com\/jschanck\/crlite\/tree\/microbench","author":"Schanck John","year":"2026","unstructured":"John Schanck. rust-query-crlite microbenchmark extension. https:\/\/github.com\/jschanck\/crlite\/tree\/microbench, 2026."},{"key":"e_1_3_2_1_45_1","unstructured":"John M Schanck. CRLite: Fast private and comprehensive certificate revocation checking in Firefox. https:\/\/hacks.mozilla.org\/2025\/08\/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox\/."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00128"},{"key":"e_1_3_2_1_47_1","unstructured":"Filippo Valsorda. The Static Certificate Transparency API. https:\/\/github.com\/C2SP\/C2SP\/blob\/main\/static-ct-api.md."},{"key":"e_1_3_2_1_48_1","volume-title":"Cloudflare, 2024","author":"Westerbaan Bas","year":"2024","unstructured":"Bas Westerbaan. The state of the post-quantum Internet. Cloudflare, 2024. https:\/\/blog.cloudflare.com\/pq-2024\/."},{"key":"e_1_3_2_1_49_1","volume-title":"May","author":"Wilson Kathleen","year":"2022","unstructured":"Kathleen Wilson. Revocation Reason Codes for TLS Server Certificates, May 2022. https:\/\/blog.mozilla.org\/security\/2022\/05\/16\/revocation-reason-codes-for-tls-server-certificates\/."},{"key":"e_1_3_2_1_50_1","volume-title":"Christo Wilson. Analysis Of SSL Certificate Reissues And Revocations In The Wake Of Heartbleed. In ACM Internet Measurement Conference (IMC)","author":"Zhang Liang","year":"2014","unstructured":"Liang Zhang, David Choffnes, Tudor Dumitras, Dave Levin, Alan Mislove, Aaron Schulman, and Christo Wilson. Analysis Of SSL Certificate Reissues And Revocations In The Wake Of Heartbleed. In ACM Internet Measurement Conference (IMC), 2014."}],"event":{"name":"SIGCOMM '26: ACM SIGCOMM 2026 Conference","location":"Colorado Convention Center Denver CO USA","acronym":"SIGCOMM '26","sponsor":["SIGCOMM ACM Special Interest Group on Data Communication"]},"container-title":["Proceedings of the ACM SIGCOMM 2026 Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3789240.3829108","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,11]],"date-time":"2026-08-11T18:45:40Z","timestamp":1786473940000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3789240.3829108"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8,11]]},"references-count":50,"alternative-id":["10.1145\/3789240.3829108","10.1145\/3789240"],"URL":"https:\/\/doi.org\/10.1145\/3789240.3829108","relation":{},"subject":[],"published":{"date-parts":[[2026,8,11]]},"assertion":[{"value":"2026-08-11","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}