HN user

leftbehind

32 karma
Posts0
Comments14
View on HN
No posts found.

:)

Looking at digicert[1], if a revocation request is submitted, the owner must approve it. What happens if I just don't approve it?

So in this case, this is the happy-case where you as the owner wish to simply realize the cancellation a cert that you are no longer using.

A different workflow applies, such that you have the private key you instead send a POST to 'https://problemreport.digicert.com/api/keys/compromised' with the private key in the JSON body and it will be queued. It is mandatory Baseline Requirements wise to cancel the certificate within 24 hours in the compromised case - usually instant if the pk matches cert - with the expectation that of course the owner will not go this route.

IIRC, if you have a private key you can be able to force a revocation regardless of what the owner wants. In some such as Let's Encrypt it is fully automated.

If this is a repo private, you should be realize it with a private CA that you import or is on every corp machine.

Baseline Requirements force a revocation within x hours on key disclosure.

We enroll them as standard fido/webauthn - I hate the other modes.

I agree it requires significantly more work when you can't just call the locksmith for a new one -- IT -- if you lose one on your personal account you can only go get the spare key hidden under the doormat, a printed code in your safe, or lose the account.

The Tesla owner in the article intentionally rammed his car repeatedly into a Waymo then publicly said Waymos kept hitting his car???

How stupid do you have to be to do this when both your vehicle AND the other vehicle continuously record at all times from every angle and stream it to the cloud?