Comment on Decreasing Certificate Lifetimes to 45 Days
atzanteol@sh.itjust.works 7 hours agoIt’s being deiven by the browsers. Shorter certs mean less time for a compromised certificate to be causing trouble.
Comment on Decreasing Certificate Lifetimes to 45 Days
atzanteol@sh.itjust.works 7 hours agoIt’s being deiven by the browsers. Shorter certs mean less time for a compromised certificate to be causing trouble.
helix@feddit.org 6 hours ago
most trouble is probably caused in the first few days. Doesn’t matter if it’s 45 or 90 days, it would have to be a few hours to be meaningfully short. Given that automating things like this is annoying sometimes, you’ll be sure people will max out the 45 days…
I’m pretty sure it’s the SSL seller lobby just wanting more money, tbh. Selling snake oil security.
Passerby6497@lemmy.world 2 hours ago
I know from professional experience that this is a stupid as fuck idea that leads to outages. One of the many reasons I’m working to automate those annoying ones.
mbirth@lemmy.ml 3 hours ago
And selling “certificate automation” tools.
False@lemmy.world 4 hours ago
Yeah you can still do a lot of damage in a few hours, but 45 days is a meaningful reduction in exposure time from year+