Lamassu IoT Docs

Certificate validation

Publish the status of identities through OCSP and CRL.

Issuance proves who signed a certificate; validation tells you whether it should still be accepted. Lamassu publishes status through two complementary mechanisms.

Choose a mechanism

Use OCSP when the consumer is online and needs to check the latest status of a specific certificate.

Use a CRL when validation must happen locally, offline or over a high volume of certificates. The consumer periodically downloads a signed list and keeps it until the next update.

Many environments use both: OCSP as the primary check and a CRL as the local or fallback mechanism.

On this page