Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thank you for the detailed explanation. I was not aware that there were rules enforcing such actions.

The linked PDF answers the question why corrupted software stacks do not qualify for forced revocation. Section 10.2.4 (which is the lever for 13.1.5) requires (but not limited to that) a private key to be "communicated" to restricted parties before a revocation might be considered.

--> For the small fee of some downvotes i learned that any cloud based service storing private keys for end users qualifies for a revocation - as long as the CA knows about it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: