Windows Live Mail revocation warning

I don't think Let's Encrypt is going to generate a CRL, just to make sure a single discontinued mail client works? They've made a choice to issue only signed OCSP statuses and don't use CRL's. So I'm guessing that was a deliberate choice, not something they decided lightly.

The mail client expects these CRL data inside the certificate, which is signed by Let's Encrypt. Furthermore, it would be insane to generate a CRL without using it for revocation checking! That's the whole point to a CRL! You can't expect Let's Encrypt to maintain a seperate bunch of certificates with a "fake" CRL. That's probably against the CA/B Forum rules too..

I guess that's something you should ask MS indeed, but don't get your hopes up..

1 Like