Hey David,
Are there any ways of revoking a service's key and should it be included as a control port function? For example, in the case that the master key is kept offline but the host and its descriptor signing key are compromised, the box could be run for a period of time(?) until the keys expire and need to be re-signed. That window could be forcefully closed remotely with a revocation that reports that key as compromised. I don't know how big that window is so I don't know how big of a risk it ends up being.
@