Comment The CA should be able to revoke (Score 1) 97
You cannot rely on DNS as controlled by the Subject only. The Issuer should be able to revoke a certificate and it does not control the corresponding DNS.
Their inventory consists mostly of blackberries.
And PlayBooks!
"If the code and the comments disagree, then both are probably wrong." -- Norm Schryer