Hacker News new | ask | show | jobs
by hamandcheese 1486 days ago
….and I assume the revocation can’t be back-dated?
1 comments

timestamps must come from a globally recognized signed source, like digicert or verisign.
The CA could backdate the CRL’s revocation timestamp if they wanted, but it seems unlikely and presumably it’s not allowed.