3 ms·
How would revoking a CA's certificate work? In particular: * The certificates that they already issued would keep working, right? Their customers would just ne
by jackowayed 16y ago
How would revoking a CA's certificate work? In particular:
* The certificates that they already issued would keep working, right? Their customers would just need to find another CA when they need to renew their certificates? I'm pretty sure that that's correct, because they're not talking about having browsers remove a CA from the trusted list. (They couldn't really. The one on the trusted list is Cybertrust, not Etisalat.)
* In that case, how do they even revoke the certificate? If they keep a copy of the certificate, wouldn't it still be able to generate valid certificates? Or is it somehow setup such that Cybertrust can easily revoke the certificate? I can't really think of a great way to do that given how I think the certificates work in general. I guess it could require a temporary key, say for the month. But I don't see how that would stop them from signing things with the temporary key that they have for August and just saying that the date it was issued is sometime in August 2010.
* Even if I'm wrong about that, if I'm right that certificates that they've issued would keep working, couldn't they generate a bunch of wildcard certificates for google.com, facebook.com, etc. right now and keep those in case they want to use them for spying?
- staktrace 16y agoI believe to revoke a certificate Verizon/CyberTrust would have to issue a revocation cert and then send that to the browser vendors. The browsers would be patched with the new revocation cert, and would reject any certificate chain that included the (now revoked) Etilsalat cert. Even if Etilsalat generates wildcard certs right now, they will be signed using Etilsalat as the issuer, and so will contain the revoked cert in the certificate chain.
- tptacek 16y agoThere are protocols (like OCSP) for doing online/realtime revokation, so that Verizon can announce that the Comtrust cert is invalid. They're kind of a mess, and they're often off by default. Mozilla should just shitcan the GTE root cert (Apple probably won't, because of the iPhone relationship, but Mozilla would be enough).