Status & revocation

Revocation

Process

Request revocation if a private key is lost, exposed or suspected compromised, if the certified identity is no longer valid, or if the certificate was issued in error. Verified key-compromise reports are acted on without delay; other verified requests are processed within one business day.

How to request

E-mailpki@manufactai.com – subject “Revocation request”, include serial number or certificate, reason, and a callback contact
Self-serviceHolders of a client certificate can revoke it directly: step ca revoke --cert cert.pem --key key.pem --reasonCode keyCompromise. Server certificates carry serverAuth only and cannot authenticate this call – report those by e-mail and we revoke them.
VerificationRequests are checked against the contact agreed with the subscriber before they are executed. A request proven by possession of the private key needs no further verification and is executed immediately.

How revocation takes effect

Passive The issuing CA refuses renewal of revoked certificates immediately. Because our certificates are short-lived (≤ 90 days, most ≤ 24 h), a revoked certificate ages out quickly.

Active The CRL is regenerated by the CA on every revocation and republished at http://pki.manufactai.com/manufactai-issuing-ca-1.crl within 15 minutes; caches may add up to 15 minutes. Its nextUpdate is 7 days out, which is headroom for CA maintenance – not the publication delay. Relying parties with strict requirements should fetch it at least daily.

Currently revoked certificates

Serial (hex)RevokedReason
64090648010E372F28FF9956D6255C212026-08-23 14:31 UTCcessation_of_operation
C8779B1421820A7A6B0E226094398C4A2026-08-23 14:31 UTCcessation_of_operation