Maximum Size of CRL


Is there a CRL size that is beyond a practical limit? I did not find anything in the RFC. Is there any limit at all on the size of CRLs?

Best Answer

I don't think there is a size limit, though other practical and security limitations should limit their size. The largest I've seen was one from Thawte at ~5MB. Most CRLs are distributed with Delta locations so clients don't need to constantly pull the whole thing.