▲ 192 ▼ Sysadmins slam Apple’s SSL/TLS cert lifespan cuts (www.theregister.com) submitted 2 years ago by misk@sopuli.xyz to c/technology@lemmy.world 81 comments fedilink hide all child comments
[–] kn33@lemmy.world 15 points 2 years ago (4 children) It is an enterprise thing, yes. permalink fedilink source parent hideshow 4 child comments replies: [–] jbk@discuss.tchncs.de 8 points 2 years ago (3 children) $300 sounds ok for an enterprise thing permalink fedilink source parent hideshow 3 child comments replies: [–] kn33@lemmy.world 6 points 2 years ago (2 children) It's more of an issue when it's every 90 days. Even worse is the labor cost to replace the certificate on everything that needs it every 90 days. permalink fedilink source parent hideshow 2 child comments replies: [–] pixely@lemmy.world 1 point 2 years ago (1 child) Are these genuinely being hand rolled in an enterprise environment? Unless it’s completely impossible to automate then I can’t be sympathetic to companies that are just doing it wrong. permalink fedilink source parent hideshow 1 child comment replies: [–] kn33@lemmy.world 3 points 2 years ago There's lots of equipment that can't accept certificates automatically. If they can, it might be in a closed off way that's difficult to impossible to reverse engineer. If you can, that's still a lot of skill and labor, which drives up the cost. They also might find out that it would be insecure to do it automatically. permalink fedilink source parent
[–] jbk@discuss.tchncs.de 8 points 2 years ago (3 children) $300 sounds ok for an enterprise thing permalink fedilink source parent hideshow 3 child comments replies: [–] kn33@lemmy.world 6 points 2 years ago (2 children) It's more of an issue when it's every 90 days. Even worse is the labor cost to replace the certificate on everything that needs it every 90 days. permalink fedilink source parent hideshow 2 child comments replies: [–] pixely@lemmy.world 1 point 2 years ago (1 child) Are these genuinely being hand rolled in an enterprise environment? Unless it’s completely impossible to automate then I can’t be sympathetic to companies that are just doing it wrong. permalink fedilink source parent hideshow 1 child comment replies: [–] kn33@lemmy.world 3 points 2 years ago There's lots of equipment that can't accept certificates automatically. If they can, it might be in a closed off way that's difficult to impossible to reverse engineer. If you can, that's still a lot of skill and labor, which drives up the cost. They also might find out that it would be insecure to do it automatically. permalink fedilink source parent
[–] kn33@lemmy.world 6 points 2 years ago (2 children) It's more of an issue when it's every 90 days. Even worse is the labor cost to replace the certificate on everything that needs it every 90 days. permalink fedilink source parent hideshow 2 child comments replies: [–] pixely@lemmy.world 1 point 2 years ago (1 child) Are these genuinely being hand rolled in an enterprise environment? Unless it’s completely impossible to automate then I can’t be sympathetic to companies that are just doing it wrong. permalink fedilink source parent hideshow 1 child comment replies: [–] kn33@lemmy.world 3 points 2 years ago There's lots of equipment that can't accept certificates automatically. If they can, it might be in a closed off way that's difficult to impossible to reverse engineer. If you can, that's still a lot of skill and labor, which drives up the cost. They also might find out that it would be insecure to do it automatically. permalink fedilink source parent
[–] pixely@lemmy.world 1 point 2 years ago (1 child) Are these genuinely being hand rolled in an enterprise environment? Unless it’s completely impossible to automate then I can’t be sympathetic to companies that are just doing it wrong. permalink fedilink source parent hideshow 1 child comment replies: [–] kn33@lemmy.world 3 points 2 years ago There's lots of equipment that can't accept certificates automatically. If they can, it might be in a closed off way that's difficult to impossible to reverse engineer. If you can, that's still a lot of skill and labor, which drives up the cost. They also might find out that it would be insecure to do it automatically. permalink fedilink source parent
[–] kn33@lemmy.world 3 points 2 years ago There's lots of equipment that can't accept certificates automatically. If they can, it might be in a closed off way that's difficult to impossible to reverse engineer. If you can, that's still a lot of skill and labor, which drives up the cost. They also might find out that it would be insecure to do it automatically. permalink fedilink source parent