3 ms·
> If we had an incident where we needed to revoke every single one of those certificates at the same time, the resulting CRL would be over 8 gigabytes. I don't
by luhn 4y ago
> If we had an incident where we needed to revoke every single one of those certificates at the same time, the resulting CRL would be over 8 gigabytes.
I don't know much about this stuff, so apologies if this is a silly question:
If you needed to revoke all the certificates, couldn't you just revoke the handful of intermediary certificates and call it a day? I assume you'd want to revoke them anyways if there's a situation severe enough that merits revoking 200 million certificates.
- mholt 4y agoIt's a good question, if I read you rightly. There is no "handful" of intermediate certificates -- there are precisely 4 (for Let's Encrypt [0]) and they are essentially on-line root certificates. And if those certificates aren't even compromised, revoking them would only harm the ecosystem. [0]: https://letsencrypt.org/certificates/ https://letsencrypt.org/certificates/
- shallichange 4y agoAccording to the link you posted, there are intermediate CAs. Those could be revoked and effectively revoke all the end entity certificates.
- tialaramex 4y agoWhen they write "essentially on-line root certificates" they don't mean that they're literally on-line root certificates, because that's prohibited. They're essentially on-line root certificates because they serve most of the function that such roots would serve if they were allowed. There aren't a bunch more available to replace them, so this means recovery now requires a key ceremony, figure on a week to a month to arrange that. Whereas if you're able to "just" revoke 10 million end entity certificates you can recover immediately.
- mcpherrinm 4y agoYes, it is likely we’d revoke an intermediate if a significant fraction of all issued certs had to be revoked. But we do want our revocation infrastructure to support revoking all certs if needed. We have a set of backup intermediates that can be activated if we had to revoke the active ones for any reason, so the disruption wouldn’t be too high hopefully. (I work at Let’s Encrypt, but this is my own opinion and not that of my employer)