Check valid certificates when issuing for IP certificates

Yes, very true.

As background, Let's Encrypt's shortlived certs currently have a CRL URL in them and are revocable. However, back in April the plan was to eventually remove the CRL URL from shortlived certs. See: What's the future of OCSP stapling? Is CRL reintroducing the downtime problem? - #16 by aarongable

Note carefully the distinction between the cert itself having a CRL URL and the possibility of a shortlived cert still being revocable and appearing in a CRL dataset.

General shortlived profile info: Profiles - Let's Encrypt

2 Likes