Disclaimer: I’ve been an engineer on various CAs in the past.
If you run into this issue, contact the CA directly and not Cloudflare.
The CA is required to handle your request within 24 hours. If they do not, that is an incident for the CA.
If you run into this issue, contact the CA directly and not Cloudflare.
The CA is required to handle your request within 24 hours. If they do not, that is an incident for the CA.
I don't think it makes a significant difference (I believe browsers don't implement revocation in any meaningful way), but the option exists.
Edit: Firefox seems to check revocation by default. https://revoked.badssl.com/ if you want to test.
And CF has no obligation to revoke the cert when it's no longer needed, nor to act as a free middleman between domain owner and CA.
Cloudflare could make this much easier by revoking the cert when the customer moves away from them. They probably should do this.