There are several reasons to revoke a certificate, the most popular one being compromise of the private key.

My question is:
What happens if there is a need to revoke the certificate of a certificate authority?

Does this mean that all the certificates it has signed should be considered revoked?
This seems reasonable, since the CA will be issued a new certificate hence a new key-pair.

On the other hand, what would be the process to revoke and reissue possibly hundreds of certificates the specific CA has already issued so far?

I am confused on the consequences of revoking a CA certificate.
Could someone please elaborate on this?

Edit
Report