Re: CRL for decommissioned CA

2019-09-17 Thread Wayne Thayer via dev-security-policy
gt; Both of them was revoked but CRL endpoint is unavailable now with HTTP 404 > error response. > OCSP also fails. > > Is it OK to abandon CRL for the decommissioned CA even if there are still > unexpired certificates? > The certificates was revoked but we have no way to validate it in a

CRL for decommissioned CA

2019-09-17 Thread nenyotoso--- via dev-security-policy
=524524172 (you can browse all issued certificates from the sub-CA with https://crt.sh/?Identity=%25=1419) Both of them was revoked but CRL endpoint is unavailable now with HTTP 404 error response. OCSP also fails. Is it OK to abandon CRL for the decommissioned CA even if there are still