Confirmed users, Administrators
5,526
edits
(continued drafting text) |
(continued drafting text) |
||
| Line 67: | Line 67: | ||
# Eve has now managed to deny service to Alice, by using the policy for abuse | # Eve has now managed to deny service to Alice, by using the policy for abuse | ||
In order to prevent this type of denial of service, the person requesting that a TLS certificate be revoked for keyCompromise must have previously demonstrated or must be able to currently demonstrate possession of the private key of the certificate before the CA revokes all instances of that key across all subscribers. | |||
Currently there is not a standard way to demonstrate possession of the private key. Here are a few ways that CAs may confirm possession of the private key: | |||
* TO DO | |||
* | |||
== OCSP and CRL == | == OCSP and CRL == | ||