3 ms·
The Baseline Requirements for publicly-trusted CAs (section 4.9.1.1) require timely revocation of mis-issued certificates - either 24 hours or 5 days depending
by pfg 7y ago
The Baseline Requirements for publicly-trusted CAs (section 4.9.1.1) require timely revocation of mis-issued certificates - either 24 hours or 5 days depending on the reason. I'm not entirely certain which is applicable here, but I'd assume Let's Encrypt's hands are tied in this case.
- wbond 7y agoThat is a very useful bit of info. I guess if the mis-issuance happened on Friday evening PT, then fives days is March 4th.
- thenewnewguy 7y agoThe misissuences have happened over the last several months (since at least December 2019), but it does seem that it was _discovered_ on Friday.
- djsumdog 7y agoI'm glad they decided on the 24 hours, unlike CAs like Comodo which really shouldn't still be a CA after all their fuckups.
- wowaname 7y agoHaving too low of a reactionary period can be equally devastating; customers need to have ample time to react to the issue so they don't panic and deploy something buggy without testing beforehand.