# Is there a CRL push infrastructure for Linux that can be hooked into?

**URL:** <https://community.letsencrypt.org/t/is-there-a-crl-push-infrastructure-for-linux-that-can-be-hooked-into/236710>\
**Category:** Client dev\
**Created:** [April 24, 2025, 10:06pm UTC](https://community.letsencrypt.org/t/is-there-a-crl-push-infrastructure-for-linux-that-can-be-hooked-into/236710 "2025-04-24T22:06:19Z")\
**Posts on this page:** 1\
**Showing post:** 12

<div class="post-metadata">

**Author:** ![jesperkristensen](https://avatars.discourse-cdn.com/v4/letter/j/46a35a/32.png) [@jesperkristensen](https://community.letsencrypt.org/u/jesperkristensen)\
**Post date:** [April 27, 2025, 4:34pm UTC](https://community.letsencrypt.org/t/is-there-a-crl-push-infrastructure-for-linux-that-can-be-hooked-into/236710/12 "2025-04-27T16:34:24Z")

</div>

Yes, certificate validation on Linux is a mess. As others have said different applications require a root store in different formats or locations, but it is worse than that. Most fill the content of these root stores by copying Mozilla's root store and removing Mozilla-specific attributes from the roots because applications can't read these attributes. But Mozilla has repeatedly said that using their root store while ignoring these attributes is insecure.

---

_[View the full topic](https://community.letsencrypt.org/t/is-there-a-crl-push-infrastructure-for-linux-that-can-be-hooked-into/236710)._
