Effective revocation is a hard problem. Should we abandon revocation in the MTC WebPKI and rely instead on the expiration of short-lived certificates? Or might there be a better solution? In this talk, Rob will introduce an idea for a lightweight revocation mechanism for MTCs that avoids introducing any PQC signatures and that aims to avoid various deployment hurdles that have plagued other revocation mechanisms in the past.
Speaker
A Distinguished Engineer at Sectigo, Rob implements PKI systems, maintains several popular open-source PKI projects (notably crt.sh and pkimetal), and has been known to contribute to standards efforts (co-author of the CAA and CTv2 RFCs).