Certificate Lifecycle Service  ·  View 15 of 21  ·  Runtime

Revocation and Bulk Re-Issuance Under an External Deadline

What happens when a CA tells the platform its certificates will stop being trusted in 24 hours.

Editable source SVG draw.io All views
Trigger Key compromise CA mandate 24 h or 5 d Intermediate distrust Decide Blast radius query registry by authority Two-person approval Re-issue first Bulk order queue rate-limit aware Second CA account pre-validated Install and verify Delivery adapters Probe sweep new serial serving Revoke Revocation record reason + actor CRL and OCSP ≤ 5 min p95 Evidence Deadline report ≤ 18 h of 24 h Rehearsal record twice a year not yet serving Revocation and Bulk Re-Issuance Under an External Deadline Risk / gap Application we own Decision point Queue / topic External / third party Interface / broker Data store Security / platform failure / alternate Re-issue precedes revoke on purpose. Revoking first turns a compromise into a self-inflicted outage; for a key known to be in an attacker's hands, the order inverts and the outage is accepted. v 1.0 · owner Security Platform Architecture · date 2026-09

The ordering decision

  • Re-issue precedes revoke. Revoking first turns a compromise notice into a self-inflicted outage across every affected endpoint.
  • For a key known to be in an attacker's hands, the order inverts and the outage is accepted — and that inversion is a declared decision with an approver, not an improvisation.

Capacity is a designed number

  • Bulk re-issuance of the full public-trust population: ≤ 18 hours, sized to complete inside a 24-hour deadline with margin (stated assumption).
  • Revocation published and observed by all validating endpoints: ≤ 5 minutes p95, ≤ 15 minutes p99, measured by a daily synthetic canary rather than assumed.
  • The bulk path is rehearsed twice a year against a representative subset. An unrehearsed bulk path is an untested one.

Risk

  • Two-person control on bulk operations exists because the failure mode of this flow is revoking certificates that should not have been revoked, at scale, quickly.
  • Revocation checking is soft-fail in most browsers. The platform declares a posture per relying-party class; an undeclared class is treated as a defect.