you are viewing a single comment's thread
view the rest of the comments
[–] 31 points 2 years ago (1 child)

Lame. 45 days? 10 days for DCV? How common are exploits involving old certificates anyway? And automated cert management is just another exploit target. Do they seriously think an attacker who pwns a server can't keep the automatic renewals running?

  • source
  • hideshow 1 child comment
  • [–] 32 points 2 years ago

    The solution, according to Sectigo's Chief Compliance Officer Tim Callan, is to automate certificate management — unsurprising considering the firm sells software that does just this.

  • source
  • parent