3 ms·
What should be the proper process then? Should Apple reply to all revocation requests asking for a proof that the certificate has really been compromised? OCSP
by abiogenesis 6y ago
What should be the proper process then? Should Apple reply to all revocation requests asking for a proof that the certificate has really been compromised? OCSP or CRL revocations are easy to revert, so why risk letting a compromised certificate to be used for an extended amount of time?
- jchw 6y agoBeats me. Apple could just give developers full discretion, which would lower the amount of time it takes to get a really compromised certificate even more. Presumably, there is some good reason to have manual discretion, otherwise, why have it?
- bentcorner 6y agoI agree that HP was careless here but IMO Apple should learn here that developers who ask for a cert revocation may not understand the consequences or the cases where this is necessary. I have no idea what the cert revocation workflow looks like, but providing cases where it should and shouldn't be used would be useful. It's still certainly possible that this falls squarely on HP and there's only so much you can do when someone is determined to blow their foot off.
- tgsovlerkhgsel 6y agoAs far as I know, CRL revocations are considered irreversible if done with any reason except certificateHold.