> the scope of the main project if ~120 certs across a similar number of 
> vendors. One of the home grown applications also hardcode the name of the 
> certificate into the application and will require not only certificate update 
> in coordination with the vendors but code changes on 120 certs in 12 days.

It seems likely to me that these applications won't actually support OCSP and 
updating any CRLs in use may well be a manual process too. So, if the 
certificates were revoked, would your applications actually notice at all? It's 
quite different from them expiring which is coded into the certificate itself.

Kind Regards

Rich
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to