135
TLS Certificate Lifetimes Will Officially Reduce to 47 Days (in 2029)
(www.digicert.com)
A community dedicated to the profession of IT Systems Administration
No generic Lemmy issue posts please! Posts about Lemmy belong in one of these communities:
[email protected]
[email protected]
[email protected]
[email protected]
This will be so much fun for people with legacy systems
Self signed certs about to get even more popular.
Tony Stark was able to build his CA in a cave! With a bunch of dice!
Self signed certs still have to abide. It’s the browser that checks it not the issuer. Now granted in most cases you already get a non trusted warning that most sysadmins skip…
The cert is what tells the browser how long it lasts, so I'm not sure how the browser can stop you from using a 10 year self signed cert or one from your own CA
If the browser sees it expires too far in the future, it could throw a warning or error.
I doubt any of them will actually do it, but it's possible.
Most browsers do this for certs with a lifetime longer than 398 days issued after 2020, which is one aspect of why so many websites use a 1 year validity period for their certs.
Or just spin up a new one all the time?
This way it will gradually ramp up the pain tho. If they went straight to 47 days, basically the entire internet would be gone for a few days.
Self signed certs still support longer time frames
If you need to expose a legacy system to the internet we have bigger issues