Request revocation if a private key is lost, exposed or suspected compromised, if the certified identity is no longer valid, or if the certificate was issued in error. Verified key-compromise reports are acted on without delay; other verified requests are processed within one business day.
How to request
| pki@manufactai.com – subject “Revocation request”, include serial number or certificate, reason, and a callback contact | |
| Self-service | Holders of a client certificate can revoke it directly: step ca revoke --cert cert.pem --key key.pem --reasonCode keyCompromise. Server certificates carry serverAuth only and cannot authenticate this call – report those by e-mail and we revoke them. |
| Verification | Requests are checked against the contact agreed with the subscriber before they are executed. A request proven by possession of the private key needs no further verification and is executed immediately. |
How revocation takes effect
Passive The issuing CA refuses renewal of revoked certificates immediately. Because our certificates are short-lived (≤ 90 days, most ≤ 24 h), a revoked certificate ages out quickly.
Active The CRL is regenerated by the CA on every revocation and republished at http://pki.manufactai.com/manufactai-issuing-ca-1.crl within 15 minutes; caches may add up to 15 minutes. Its nextUpdate is 7 days out, which is headroom for CA maintenance – not the publication delay. Relying parties with strict requirements should fetch it at least daily.
Currently revoked certificates
| Serial (hex) | Revoked | Reason |
|---|---|---|
| 64090648010E372F28FF9956D6255C21 | 2026-08-23 14:31 UTC | cessation_of_operation |
| C8779B1421820A7A6B0E226094398C4A | 2026-08-23 14:31 UTC | cessation_of_operation |