6 ms·
Take a look at the "Baseline Requirements for the Issuance and Management of Code Signing Certificates"[0] - specifically section 13.1. Here's the most relevan
by ecdavis 6y ago
Take a look at the "Baseline Requirements for the Issuance and Management of Code Signing Certificates"[0] - specifically section 13.1.
Here's the most relevant excerpt:
> A CA MUST revoke a Code Signing Certificate in any of the four circumstances: (1) the Application Software Supplier requests revocation, (2) the subscriber requests revocation, , (3) a third party provides information that leads the CA to believe that the certificate is compromised or is being used for Suspect Code, or (4) the CA otherwise decides that the certificate should be revoked.
[0] https://cabforum.org/baseline-requirements-code-signing/ https://cabforum.org/baseline-requirements-code-signing/