ParentFull threadgrahamedgecombe·OCSP and CRLs allow a CA to revoke an SSL certificate (albeit with a varying degree of browser support).View on HN