10
There are several reasons to revoke a certificate, the most popular one being compromise of the private key.
My question is:
What happens if there is a need to revoke the certificate of a certificate authority?
Does this mean that all the certificates it has signed should be considered revoked?
This seems reasonable, since the CA will be issued a new certificate hence a new key-pair.
On the other hand, what would be the process to revoke and reissue possibly hundreds of certificates the specific CA has already issued so far?
I am confused on the consequences of revoking a CA certificate.
Could someone please elaborate on this?