7 ms·
This is not true. In Let's Encrypt/ACME for example, you can simply obtain authorizations for all the domains a certificate is valid for and request revocation
by pinjiz 7y ago
This is not true. In Let's Encrypt/ACME for example, you can simply obtain authorizations for all the domains a certificate is valid for and request revocation [1]. The only thing you still need to revoke the certificate, is the certificate itself. The certificate can be obtained from CT logs.
[1] https://tools.ietf.org/html/rfc8555#section-7.6 https://tools.ietf.org/html/rfc8555#section-7.6