Yes. The validation -- authorization -- lasts for a certain amount of time. I think it's currently 90 days, though they intend to lower it further: Upcoming API changes The attacker can continue issuing certificates until it expires, covering a total of about 179 or 180 days.
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| Revoke a authorization-resource | 5 | 3147 | August 28, 2015 | |
| Revoking certificates with different LE Accounts | 4 | 299 | June 25, 2024 | |
| Find out how has been done | 11 | 1304 | September 20, 2019 | |
| Proving any or all identifier for certificate revocation | 3 | 1033 | February 13, 2020 | |
| Can't revoke certificate issued by compromised host | 1 | 784 | December 12, 2018 |