Comment The CA should be able to revoke (Score 1) 97
You cannot rely on DNS as controlled by the Subject only. The Issuer should be able to revoke a certificate and it does not control the corresponding DNS.
Their inventory consists mostly of blackberries.
And PlayBooks!
That's the thing about people who think they hate computers. What they really hate is lousy programmers. - Larry Niven and Jerry Pournelle in "Oath of Fealty"