4 ms·
If Let's Encrypt needs to revoke the certificate prior to expiration (for compliance or any other reason) ARI can let a client know in advance of the revocation
by jaas 4y ago
If Let's Encrypt needs to revoke the certificate prior to expiration (for compliance or any other reason) ARI can let a client know in advance of the revocation. The client can then renew early and avoid a disruption in service.
Clients that renew based on ARI can also help Let's Encrypt avoid disruptive load spikes since ARI signals can spread out renewals.
- cm2187 4y agoHa ok, so it's specifically for revocations. Still a revocation would be done manually. It feels odd someone would revoke their certificate and not think about re-issuing a new one.
- jaas 4y agoAny CA can revoke a certificate they issued without the subscriber being involved, so subscribers aren't necessarily revoking their own certs. When that happens ARI is a more efficient automated mechanism by which to let people know that a revocation is coming and they should renew.
- WirelessGigabit 4y agoWhen revoking a certificate it gives peace of mind that whatever system is using that certificate will pull a new one.
- mcpherrinm 4y agoIf a certificate was detected to be mis-issued after the fact, it may need to be revoked. And in fact many certificates may need to be revoked. This has happened to Let's Encrypt a few times already, and was the main motivation for this API. Some existing systems like the Caddy server use OCSP to detect if a cert is revoked and can renew immediately, but ARI allows allows a certificate to be reissued before the old one is revoked. There are other related things that aren't specifically revocation: For example, certificates contain embedded Certificate Transparency timestamps from CT logs. If one or more of those logs fail, we might want to reissue those certificates before browsers distrust the logs. (I work for Let's Encrypt)
- mholt 4y ago> Some existing systems like the Caddy server use OCSP to detect if a cert is revoked and can renew immediately, but ARI allows allows a certificate to be reissued before the old one is revoked. Hi Matthew :) Caddy still serves a perfectly valid "GOOD" response from the OCSP responder while it renews the certificate, so the certificate is good as not-revoked until that OCSP staple expires. (As we know, revocation is broken anyway. We should deprecate it for public PKI and go with short cert lifetimes instead.)