General · GraphQL enum

RevocationSource enum

Where a revocation verdict came from, which determines how much it is worth. Reference: RFC 6960 - Online Certificate Status Protocol

Values

Enum Value Description

NONE

No source was consulted, which pairs with an UNKNOWN status.

OCSP_STAPLED

An OCSP response the service stapled to its own handshake. The cheapest evidence there is: it arrives inside a handshake the scan already performs and is signed by the issuer, so it verifies offline.

OCSP_FETCHED

An OCSP responder queried directly, at the URL in the certificate's Authority Information Access extension. Costs an outbound request the stapled path avoids, and is the only source for an issuer that publishes no revocation list.

CRL

A certificate revocation list published by the issuing authority and verified against it.

Used by

  • TLS type: Reports on SSL (Secure Sockets Layer) and TLS (Transport Layer Security).

Example

Example

"NONE"