4 ms·
> However, several CAs disliked having to revoke all those certificates, because it cost them staff time (and hence money) to do so. They went so far as to chan
by profmonocle 3y ago
> However, several CAs disliked having to revoke all those certificates, because it cost them staff time (and hence money) to do so. They went so far as to change their procedures from the standard way of accepting problem reports (emailing a generic attestation of compromise), and instead required CA-specific hoop-jumping to notify them of compromised keys.
Maybe the baseline requirements need to be updated to require an automated mechanism for reporting key compromises. CAs have to revoke certs with compromised keys, but by going out of their way to increase the barrier to doing so, they're clearly not complying in good faith.
The ACME protocol (Let's Encrypt) makes this simple - just sign a request to the revocation API with the cert's private key.
- hsbauauvhabzb 3y agoI’m unsure what part of revoking certificates is labor intensive if you’re a certificate authority, given your entire purpose is to sign and revoke keys..
- wiml 3y agoI get the impression that some of the big name CAs are ... not very technology oriented, you might say. They focus on the sales side, and treat the actual issuance and revocation of certificates as an unfortunate cost center and minimize investment.
- Retr0id 3y agoI can imagine it's hard to convince a BA that they should invest in responding to requests from non-customers.
- alphager 3y agoThe CAs have automated signing and have zero labor in that part. Revoking is a manual process, infinitely more labor intensive.
- viraptor 3y agoYou need to notify the customer and then deal with the support work when they roll the key. Also they will get some blame from the customer for having to deal with the situation. All that without much extra payment. It's much more profitable to not care.
- tgsovlerkhgsel 3y agoMost of their process is 100% automated. Revoking based on free-form reports would at the very least require a human to deal with the report. Also, customer service for dealing with the certificate holder. That said, offering an API and automating as much as they can is a lot easier than receiving the reports through free-form e-mail, with followup through Mozilla's root program (https://wiki.mozilla.org/CA/Bug_Triage#Compliance_Problems_and_Incidents https://wiki.mozilla.org/CA/Bug_Triage#Compliance_Problems_a...), where the CA will have to take action or cease existing.