Re: Digicert revoking certain certs failing CNAME validation

2024-07-31 Thread Sean Donelan
Affects 83,267 certs impacting 6,807 Digicert subscribers. Less than 0.4% Digicert Domain Validated (DV) certs. As far as I know, the major browser vendors no longer show any user visible distinction between different types of certificate issuance validation. UI testing found users didn't

Re: Digicert revoking certain certs failing CNAME validation

2024-07-31 Thread Hank Nussbacher
On 31/07/2024 7:14, Peter Fisher wrote: These short and immediate revocations as well as other issues will keep happening since the CA/B has no end user representation. See my blog post from 4 years ago: https://www.iucc.ac.il/en/blog/internet-certificates/ Regards, Hank Actually it looks lik

Re: Digicert revoking certain certs failing CNAME validation

2024-07-31 Thread Tom Beecher
Not shocked. At least one company got a TRO preventing the 24h revocation. Honestly I think it's the right thing anyway. It doesn't make a ton of sense to punish everyone else because the CA itself screwed up and *created* a circumstance that happens to meet one of the 24h / no extension condition