If the certificate only lasts two months revocation isn’t necessary, just deny recertification.
Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative?
Passerby6497@lemmy.world 1 day agoCertificate revocation is a joke and has been for over a decade
DegradationDenial@feddit.nl 1 day ago
Viceversa@lemmy.world 1 day ago
And what if you need to get a new certificate?
possiblylinux127@lemmy.zip 1 day ago
You go to a different CA
Alfredolin@sopuli.xyz 1 day ago
Aren’t we back at OP’s question?
Dirk@lemmy.ml 1 day ago That’s the question of this thread. Yes.
T4V0@lemmy.pt 1 day ago
Orion browser (maybe safari?) on iOS detected the revoked certificate, and asked me to confirm before accessing the website while warning about the dangers.
Passerby6497@lemmy.world 23 hours ago
Does regular safari show the same prompt? Afaik, browsers on iOS are safari reskins, so I’m curious if they added his cert in directly, or if the onion browser actually follows standards the os browser doesn’t.
T4V0@lemmy.pt 21 hours ago
Yes, but safari doesn’t even let me ignore the warning, it has a explanation in detail, and only allows closing the website.
dogdeanafternoon@lemmy.ca 17 hours ago
You didn’t look hard enough. My router cert isn’t valid and I have to bypass the warning every time.
Randelung@lemmy.world 1 day ago
Huh, FF on Android doesn’t care.
Passerby6497@lemmy.world 1 day ago
Most browsers don’t, hence my calling revocation a joke.
So many in this thread are up in arms about something the majority of browsers don’t care about and have actively ignored for as long as I can recall
Randelung@lemmy.world 1 day ago
Yeah, I was just surprised bc the page explicitly lauds FF for checking revocation.
Passerby6497@lemmy.world 1 day ago
It may only be the desktop version, most mobile browsers aren’t as feature complete as their desktop counterparts.
But, given Google ripped revocation checking out of chromium, I wouldn’t be surprised if they nerfed it in Android too…