Hi Jeremy, This seems rather problematic. I greatly appreciated DigiCert's past consideration of this, which was to set the absolute upper bound at no greater than two weeks.
As proposed, this would effectively make 4.9.1.1 and 4.9.1.2 pointless, as it leaves it fully up to CA discretion. As we've seen with the validation methods' "any other method", CA discretion creates significant challenges for relying parties and auditors to be assured of the integrity of the Web PKI and of the technical and material factors weighing in. That is, I'm totally supportive of an approach that tries to balance 24 hours, but I think anything that allows for arbitrarily-determined revocation, as proposed, would be a big step backwards for the security and confidence in the PKI. On Thu, Jul 13, 2017 at 2:47 PM, Jeremy Rowley via Public <[email protected]> wrote: > Hi all, > > > > I took Ben’s previous ballot proposal for changing revocation timelines and > combined it with the timelines previously proposed. Basically, the > timelines were established to still require CA responsiveness but balance > with compromise notices that are received at weird hours or during holidays. > > > > Looking forward to your comments. > > > > Jeremy > > > _______________________________________________ > Public mailing list > [email protected] > https://cabforum.org/mailman/listinfo/public > _______________________________________________ Public mailing list [email protected] https://cabforum.org/mailman/listinfo/public
