Executive Summary
Facts Only
* The project aims to manage test certificates for Certificate Authorities (CAs).
* Three states are managed: valid, expired, and revoked certificates.
* Obtaining certificates requires completing a domain validation challenge using Lego.
* To check for revocation, the system polls the Certificate Revocation List (CRL) for the certificate's serial number.
* The program implements waiting periods: at least 24 hours for revoked certificates to ensure CRL processing and longer waits for expired certificates to pass their date.
* A Go webserver uses a GetCertificate callback function, selecting the correct certificate based on Server Name Indication (SNI).
* The system allows serving non-expired but revoked certificates by implementing custom logic.
* The system serves an optional plain text version of the website for testing purposes.
* Four Let’s Encrypt root certificates are mentioned, each having valid, expired, and revoked test sites.
Full Take
From the original · LetsEncrypt Blog
Have you ever needed to make sure your website has a broken certificate? While many tools exist to help run an HTTPS server with valid certificates, there aren’t tools to make sure your certificate is revoked or expired.Read the full story at letsencrypt.org
Sentinel — Human
The text reads like a detailed explanation from an experienced developer or engineer describing a complex system they built to solve a specific technical gap related to Certificate Authorities.
