mediaaustin
Member
OP
Deliverability Nerd
- Joined:
- Jul 2024
- Posts:
- 276
- From:
- Austin, US
Bought a dropped domain from an auction last week. Previous owner's SSL cert from Time4VPS is still valid for another 60 days. My server, their certificate, no revocation showing in CT logs yet.
For what it's worth, this is not purely academic. Browsers still trust it. Mail servers might too. The previous owner could theoretically still present that cert if they control any lingering DNS or CDN edge. SPF and DKIM are clean on my end, but the certificate transparency lag is real.
Has anyone mapped typical revocation delays? The RFC 6962 ecosystem feels slower than blocklist propagation, and that is saying something.
SPF, DKIM, DMARC — holy trinity ✉️
tallinnying
Member
Night Shift
- Joined:
- Aug 2024
- Posts:
- 268
- From:
- Tallinn, EE
Anyway I had this exact thing in 2023. Bought a dropped domain, previous owner's cert valid for 89 days. Idk why I do this but I wrote a cron that polled the CT logs every hour and graphed it. Took 11 days for a precertificate to show revocation.
While true; do
curl -s "https://crt.sh/..." | jq.
Sleep 3600
Done
3am code never dies. 💀
builds at 3AM, sleeps at noon
mediaaustin
Member
OP
Deliverability Nerd
- Joined:
- Jul 2024
- Posts:
- 276
- From:
- Austin, US
Just use certbot. Skill issue.
I have certbot running. That's not the point. The point is a third party still holds a cryptographically valid claim to my hostname and the revocation infrastructure is too slow to matter.
Took 11 days for a precertificate to show revocation
11 days is actually faster than I expected. Did you ever see OCSP respond revoked before the CT log caught up? In my current case the OCSP responder still says "good" too.
SPF, DKIM, DMARC — holy trinity ✉️
tallinnying
Member
Night Shift
- Joined:
- Aug 2024
- Posts:
- 268
- From:
- Tallinn, EE
Did you ever see OCSP respond revoked before the CT log caught up?
Never. In my case the OCSP "good" outlasted the CT precertificate by about 36 hours. So you had this window where the log said revoked but live validation still passed.
Also hi from the night shift, I am running the same curl cron again on your domain now. Will DM you if I see movement.
builds at 3AM, sleeps at noon
lucgone
Member
Le Baguette
- Joined:
- Jul 2024
- Posts:
- 296
- From:
- Lyon, FR
In France we have a similar problem with ANSSI and their certificat électronique rules for government sites, but for commercial hosting nobody cares. I manage fifty domains for clients and I see this maybe twice a year. My solution: I contact the old host directly. Time4VPS in Vilnius, they answer in 24 hours usually, I ask them to revoke. It works.
Vive la résistance... électrique