Coincidentally, I've been thinking about this as w...
# general
s
Coincidentally, I've been thinking about this as well. One of the interesting ideas in from Hashicorp Vault, is that short lived certs that are not renewed are often simpler to manage than invalidation and CRLs. So, speculating wildly, I've been wondering instead of invalidation based on failing checks, signing a CSR and shipping a cert based on successful checks.