Skip to content

ACME passive revocation #1038

Answered by hslatman
ShoootLight asked this question in Q&A
Aug 31, 2022 · 1 comments · 3 replies
Discussion options

You must be logged in to vote

Hey Stephan,

What you've tried so far, sounds OK to me. What you're trying to do, however, is in fact active revocation. We call revocation passive when certificates have short lifetimes and thus expire frequently. Active revocation is the "classical" method of revocation, involving CRLs and OCSP.

When a certificate is revoked, this generally means that only that specific certificate is revoked, based on its serial number. This serial number is then recorded in a CRL or its revocation status can be requested using OCSP. I'm not aware of a requirement that the private key that corresponds to a certificate to be revoked MUST be marked as not usable anymore; at least not in the Web PKI. I ha…

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@maraino
Comment options

@ShoootLight
Comment options

@hslatman
Comment options

Answer selected by ShoootLight
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
needs triage Waiting for discussion / prioritization by team
3 participants