logoalt Hacker News

rvnxyesterday at 8:16 PM3 repliesview on HN

What if they get kicked out of trusted roots because non-compliant ?


Replies

wolrahyesterday at 9:52 PM

You don't get kicked out of trusted roots for non-compliance, you get kicked out for continuing to knowingly issue non-compliant certs, failing to revoke non-compliant certs in a timely fashion once discovered, etc.

Pausing issuance immediately upon discovery of a compliance issue is the absolute correct response so as long as they do their followup appropriately there is absolutely zero risk of being distrusted.

show 1 reply
nicolas_17yesterday at 8:31 PM

That's why they take incidents like this seriously and stop issuance until it's fixed. They could get kicked out of trusted roots otherwise.

nijaveyesterday at 9:06 PM

Change your config to ZeroSSL or another free ACME provider?