My last job had an Onlineshop, 4years in a row the colleague dealing with ssl wad on vacation when the cert ran out.
Comment on Anyone using 6-day certs yet?
BorgDrone@feddit.nl 4 hours agoSeveral reasons
- If a private key leaks, a shorter certificate lifespan limits the fallout
- Faster upgrades to new cryptographic standards. If some of the crypto methods used get broken, short lived certificates means they get replaced with newer methods faster
- Short lived certificates force sysadmins to automate the renewal process. This prevents expired certificates due to forgetting the manual renewal.
- Certificate lifetime and domain ownership mismatch. You could buy a 2 year certificate for somedomain.com and then sell the domain or just let it expire and have it picked up by someone else. You then have a valid certificate for a domain you no longer ow and you could MitM traffic for the new owner’s website.
UxyIVrljPeRl@lemmy.world 4 hours ago
chronicledmonocle@lemmy.world 3 hours ago
Your colleague sucked at automation. Normally, I’d say no one should be bothered on vacation, but in this case you should have called him on his vacation, since he didn’t value anyone else’s time either.
roofuskit@lemmy.world 3 hours ago
The manager sucked. There’s a lot of solutions to this issue but cross training and proper backup preparation are the most ideal ones.
undefinedTruth@lemmy.zip 2 hours ago
That was already the case with the 90 day ones. No sane person is going to be manually renewing certificates every 3 months.
pipe01@programming.dev 1 hour ago
Emphasis on “sane”