[Acme] Revoking certificates issued by an unknown ACME server

2016-01-14 Thread Hugo Landau
So while implementing revocation in my ACME client, I came to the following problem: how do you know which ACME server issued a certificate? Given an ACME server URL, one can obtain a certificate, but there is no reliable way to do the reverse. If you think about it, it might be desirable to be

Re: [Acme] Revoking certificates issued by an unknown ACME server

2016-01-14 Thread Martin Thomson
On 15 January 2016 at 17:26, Hugo Landau wrote: > This isn't sanely automatable. Correct. But it doesn't require any work to define. Do you have evidence that suggests this scenario (a certificate issued by an ACME server needs revocation by someone other than the one who

[Acme] acme - Update to a Meeting Session Request for IETF 95

2016-01-14 Thread "IETF Meeting Session Request Tool"
An update to a meeting session request has just been submitted by Stephanie McCammon, on behalf of the acme working group. - Working Group Name: Automated Certificate Management Environment Area Name: Security Area Session Requester: