Revocation exists to invalidate a certificate before its natural expiration, but a revocation mechanism only matters if clients actually check it. This article looks specifically at how browsers and applications handle revocation checking in practice, where the theory of CRLs and OCSP, covered in depth elsewhere in this series, meets the messier reality of what actually happens during a real connection.