Certificate Revocation Policies

A somewhat-related topic is here:

Not the sort of criminal activity you're talking about, but also not cybercrime. There, as here, the answer really is that it isn't the CA's issue--they certify only that the holder of the certificate demonstrated control over the domain name in question. While their TOS reserve the right to revoke certs in the case of criminal activity, they don't in any way obligate Let's Encrypt to do so, and I'm not aware of any mechanism for Let's Encrypt to consider petitions of the sort you're asking about.

And, IMO, that's as it should be. The cert doesn't demonstrate anything other than domain control, and shouldn't be seen as demonstrating anything else. And revoking it for any other reason undercuts that truth.

2 Likes