From 4b226f4f2cc119f4d9eb8d617b9c52ab5f4e72dc Mon Sep 17 00:00:00 2001 From: Carl Tashian Date: Thu, 29 Aug 2024 12:47:40 -0700 Subject: [PATCH] Update step-ca/certificate-authority-server-production.mdx Co-authored-by: Herman Slatman --- step-ca/certificate-authority-server-production.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/step-ca/certificate-authority-server-production.mdx b/step-ca/certificate-authority-server-production.mdx index d485f640..5bc147f8 100644 --- a/step-ca/certificate-authority-server-production.mdx +++ b/step-ca/certificate-authority-server-production.mdx @@ -218,7 +218,7 @@ it can be rendered unusable by an attacker through revocation. But there are downsides: CRL adds a service dependency to your PKI. -Clients check the CRL endpoint on every new connections, +Clients check the CRL endpoint on every new connection, adding significant latency to the TLS handshake, and load on your CRL endpoint.