|
|
|
|
|
by leftbehind
631 days ago
|
|
IIRC, if you have a private key you can be able to force a revocation regardless of what the owner wants. In some such as Let's Encrypt it is fully automated. If this is a repo private, you should be realize it with a private CA that you import or is on every corp machine. Baseline Requirements force a revocation within x hours on key disclosure. |
|
I didn't know about CA/Browser forum and the Baseline Requirements. Thanks, will check it out!
// Edit: Relevant section:
The Subscriber Agreement or Terms of Use MUST contain provisions imposing on the Applicant [..] the following obligations and warranties:
[...]
Protection of Private Key: An obligation and warranty by the Applicant to take all reasonable measures to assure control of, keep confidential, and properly protect at all times the Private Key [...]