3 ms·
You wouldn’t. But the CA that issued the certificate could still revoke it, correct? E.g. https://letsencrypt.org/docs/revoking/#using-a-different-authorized-ac
by HellsMaddy 5y ago
You wouldn’t. But the CA that issued the certificate could still revoke it, correct? E.g. https://letsencrypt.org/docs/revoking/#using-a-different-authorized-account https://letsencrypt.org/docs/revoking/#using-a-different-aut...
- remram 5y agoYes, from that same link you can see that whoever controls the domain can revoke those certificates (by asking Let's Encrypt to revoke it). All you need is the certificate itself (which you can get from the transparency logs e.g. crt.sh), not the private key.
- jeff_carr 5y agoIt's unclear. Do you know what CA's you currently trust on your machine? I bet you can't even identify 1 tenth of them. There are so many CA's installed by default that it's truly a massive man-in-the-middle attack whenever you might think you are safe, you are not. I would assume the CCP & the KGB control at least one of the CA's your OS currently trusts. (No doubt the NSA has one too) In debian: dpkg -L ca-certificates