I just looked up your question regarding revocation. Yes, the CAs can and should issue a
revocation list of vulnerable certificates. The X.509 certificate standard provides for such
a capability.
That the CAs haven't used it yet indicates they aren't taking this problem as seriously as
they should.
Posted Jun 17, 2008 2:41 UTC (Tue) by ringerc (subscriber, #3071)
[Link]
As far as I know most user-agents don't support, or check, a CRL. From what I've seen support
generally requires user/admin configuration and mostly seems to get used on SOE setups and
corporate intranets.
CAs say few people are getting replacements
Posted Jun 20, 2008 16:43 UTC (Fri) by akumria (subscriber, #7773)
[Link]