[All Lists] [By Thread] [By Date] [Previous] [Next]
From: R. Halevi
Subject: Can certificates be revoked?
Date: 14 Tevet 5782
uncertain, not erased
The honest answer is the uncomfortable one. We should not pretend otherwise.
The specification should state clearly: revocation is a statement about the issuer's current position, not a claim about the past. The cryptography does not lie. The signature was valid. We are changing our stance, not the history.
Let those who implement understand what they are building.
—Dov Halevi
Thread: