Re: Exceptions to 1024-bit cert revocation requirement

2013-12-23 Thread Rob Stradling
On 21/12/13 22:22, Kathleen Wilson wrote: On 12/20/13 11:45 AM, Rob Stradling wrote: To me, cert revocation means replying revoked via OCSP for that cert's serial number, and also adding that cert's serial number to the CRL. I understand that new versions of browsers will stop accepting

Re: Exceptions to 1024-bit cert revocation requirement

2013-12-23 Thread Rob Stradling
On 21/12/13 22:57, Phillip Hallam-Baker wrote: I thought that what we were trying to do here is break a deadlock where Cas wait for browsers and vice versa. I have no trouble telling a customer with a 15 year 512 bit cert that they need to change for a new one if they want it to work for ssl

Re: Exceptions to 1024-bit cert revocation requirement

2013-12-23 Thread Phillip Hallam-Baker
On Mon, Dec 23, 2013 at 8:54 AM, Rob Stradling rob.stradl...@comodo.comwrote: On 21/12/13 22:57, Phillip Hallam-Baker wrote: I thought that what we were trying to do here is break a deadlock where Cas wait for browsers and vice versa. I have no trouble telling a customer with a 15 year 512