Root CA → Intermediate CA → Leaf (hardware-bound) Drag to orbit · scroll to zoom
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

Certificate Revocation Race: CRL vs OCSP vs Stapling

This simulator visualizes the security model behind smart, hardware-bound PKI certificates — a chain of trust from Root CA through Intermediate CA to a leaf certificate whose private key never leaves its secure element — and races the three real-world methods a client uses to learn a certificate has been revoked: periodic CRL downloads, live per-connection OCSP queries, and server-side OCSP stapling. Trigger a revocation, tune the network RTT and refresh interval, and watch each method's detection latency and privacy footprint play out as animated packets on a live 3D network topology.