3 ms·
CA Baseline requirements say certificate revocation must be within 24h so a daily process may miss; a manual process on-demand or every 12hours would comply. I
by advisedwang 4y ago
CA Baseline requirements say certificate revocation must be within 24h so a daily process may miss; a manual process on-demand or every 12hours would comply.
I suspect it's more about competitiveness though. Manual processes are expensive and slow, which likely will push customers to choose other CAs. I don't think there is a market for manually operated certificates. I believe this for two reasons:
1. Because any CA can issue a certificate, you are exposed to the risk of some other CA getting hacked regardless of how secure the CA you choose is. (Although CT and CAA may mitigate this).
2. Air-gapping is neither necessary nor sufficient to be secure. Not sufficient because even an air-gapped system needs controls against insider threats, tampering of data before it gets transfered across the air-gap, attacks that breach the air-gap [1] etc. Not necessary because well run systems can be reasonably secure even without an air-gap.
[1] https://en.wikipedia.org/wiki/Air-gap_malware https://en.wikipedia.org/wiki/Air-gap_malware