# Does revocation cause additional load?

**URL:** <https://community.letsencrypt.org/t/does-revocation-cause-additional-load/25203>\
**Category:** Issuance Tech\
**Created:** [January 5, 2017, 3:50pm UTC](https://community.letsencrypt.org/t/does-revocation-cause-additional-load/25203 "2017-01-05T15:50:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 5, 2017, 3:50pm UTC](https://community.letsencrypt.org/t/does-revocation-cause-additional-load/25203/1 "2017-01-05T15:50:44Z")

</div>

> [@Cannot create new certificate](https://community.letsencrypt.org/t/cannot-create-new-certificate/25124/7):
>
> It produces additional unnecessary load on our end (…)

Offtopic: Just for my interest, where does the extra load come from? And is it significant? OCSP's need to be signed anyway and LE doesn't use CRL's.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [January 6, 2017, 7:24pm UTC](https://community.letsencrypt.org/t/does-revocation-cause-additional-load/25203/2 "2017-01-06T19:24:46Z")

</div>

Hi @osiris,

Revocation doesn’t cause any significant additional load on our end. I’m not sure where I got that idea but thinking it through & checking with others I’ve learned it’s not true. I edited my response on the initial thread to clarify that the reason revocation should be skipped short of suspecting key compromise is that it’s just extra work without a lot of tangible benefit.

Thanks for asking & prompting the thought experiment 🙂

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 6, 2017, 7:58pm UTC](https://community.letsencrypt.org/t/does-revocation-cause-additional-load/25203/3 "2017-01-06T19:58:45Z")

</div>

Well, could be there was some extra load somewhere, but good to know there isn’t!

---

<div class="post-metadata">

**Author:** ![TCM](https://avatars.discourse-cdn.com/v4/letter/t/a587f6/32.png) [@TCM](https://community.letsencrypt.org/u/TCM)\
**Post date:** [January 7, 2017, 6:59am UTC](https://community.letsencrypt.org/t/does-revocation-cause-additional-load/25203/4 "2017-01-07T06:59:49Z")

</div>

What exactly happens then? Does LE continue to sign OCSP responses with a negative status? (Not sure about the inner details of OCSP responses).

Assuming the world had globally transitioned to OCSP must-staple, would it then even reduce the load since LE could just stop signing OCSP responses at all?

---

<div class="post-metadata">

**Author:** ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)\
**Post date:** [January 9, 2017, 4:45pm UTC](https://community.letsencrypt.org/t/does-revocation-cause-additional-load/25203/5 "2017-01-09T16:45:46Z")

</div>

The CA basically keeps resigning the "REVOKED" response, like any other OCSP response. BRs state that:

> Revocation entries on a CRL or OCSP Response MUST NOT be removed until after the Expiry Date of the revoked Certificate

and

> The CA SHALL update information provided via an Online Certificate Status Protocol at least every four days. OCSP responses from this service MUST have a maximum expiration time of ten days.

So yeah, same signing load. I suppose it wouldn't be strictly necessary in a Must-Staple-only world, but probably not worth it to change the relevant RFCs and BRs since revocation is rather uncommon.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [February 8, 2017, 4:45pm UTC](https://community.letsencrypt.org/t/does-revocation-cause-additional-load/25203/6 "2017-02-08T16:45:52Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
