Problems in Revocation People don't really use CRLs! Example: Sun Security Bulletin #00198 In October 2000, two of Sun's code-signing certificates were leaked accidentally Neither IE nor Netscape supported CRL checking - users were advised to remove any such certificates manually http://sunsolve5.sun.com/secbull/certificate_howto.html