Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Certificate Revocation #6

Open
pgporada opened this issue Feb 17, 2022 · 0 comments
Open

Certificate Revocation #6

pgporada opened this issue Feb 17, 2022 · 0 comments

Comments

@pgporada
Copy link

Hi fzslin,

In the Let's Encrypt Subscriber Agreement available here, the ACME client that generated the x509v3 key pairs available at https://github.com/fszlin/lo0.in/releases agreed to the following text:

3.7. When to Revoke Your Certificate
You warrant to ISRG and the public-at-large, and You agree, that You will immediately request that
Your Certificate be revoked if: (i) there is any actual or suspected misuse or Key Compromise of the
Private Key associated with the Public Key included in Your Certificate, or (ii) any information in Your
Certificate is, or becomes, misleading, incorrect or inaccurate. You may make a revocation request to
ISRG using ACME Client Software. You should also notify anyone who may have relied upon Your
use of Your Certificate that Your encrypted communications may have been subject to compromise.

Further, the Let's Encrypt Certificate Policy states:

4.9.1.1 Reasons for Revoking a Subscriber Certificate
The CA SHALL revoke a Certificate within 24 hours if one or more of the following occurs:
...
The CA obtains evidence that the Subscriber's Private Key corresponding to the Public Key in the Certificate suffered a Key Compromise;

Due to this, the Let's Encrypt issued certificates corresponding to the private keys leaked in this repository have been revoked.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant