Skip to content

Comment on StartSSL, please revoke me – My private key has been compromisedparent

Comments

What if someone hacked your server and stole, then deleted the private key? (Backing up private keys is bad practice.)

What if the CA notices they issued a fraudulent certificate?

Hmm, I considered this possibility in a comment, incidentally two hours before yours, below. Let the CA have an ability to revoke certs, I'm not suggesting against that. I'm suggesting a method in addition to it.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.