a) if they receive a request to revoke that certificate, they can actually do so; and
b) if they need to revoke all of their certs (e.g. due to discovering a validation process failure) they don't miss any.
a) if they receive a request to revoke that certificate, they can actually do so; and
b) if they need to revoke all of their certs (e.g. due to discovering a validation process failure) they don't miss any.
And the GP used the word "all" which is what I was replying to.
In the same context, revoking the intermediate CA is bad in case some issued certificates were valid for an initial period, because then clients are unable to obtain fresh revocation information about issued certificates that would indicate the respective time of revocation (because the intermediate CA has to remain valid in order to be able to validate the signature on the OCSP response or CRL).
This is mostly not a concern in the context of TLS validation, because that usually relates only to the present time, not to times in the past, but it is relevant for code signing or other electronic signature use cases.
Dumb q, but why not just revoke/invalidate the signing certificate used to sign the certificates?