5 ms·
The only real difference I spot in the diff is ISRG not storing your certificate in its repository anymore.
by Lucent 4y ago
The only real difference I spot in the diff is ISRG not storing your certificate in its repository anymore.
- bobsmooth 4y agoThat's what I gathered.
- infogulch 4y agoIs that different from the certificate transparency log (CT)?
- zinekeller 4y agoYes, previously as part of audit requirements you are required to internally store all certificates you've issued for at least seven years. Seeing as CT is now here though (which is a much more robust system since it's tamper-resistant), storage on your own archives is no longer needed (as long as you can prove that you log them all in CTs).
- infogulch 4y agoThanks!
- buzer 4y agoIn the email that they sent they said following: The main updates are: we now link to instructions on choosing a revocation reason if you revoke a certificate. This is a requirement for Subscriber Agreements from all Certificate Authorities as of this year. Also, we've removed unneeded capitalization, removed a section that is redundant with our Certificate Policy (CP), and tweaked the wording of the requirement to "assure" control of your private key so it matches the Baseline Requirements (BRs).
- jaas 4y agoWe still store the certificate in the same ways we did, we just don't talk about it in the subscriber agreement any more as it's redundant with our CP/CPS documents.