• 0 Posts
  • 1 Comment
Joined 1 year ago
cake
Cake day: June 10th, 2025

help-circle
  • BorgDrone@feddit.nltoSelfhosted@lemmy.world•Anyone using 6-day certs yet?
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    1
    ·
    1 day ago

    Several reasons

    • If a private key leaks, a shorter certificate lifespan limits the fallout
    • Faster upgrades to new cryptographic standards. If some of the crypto methods used get broken, short lived certificates means they get replaced with newer methods faster
    • Short lived certificates force sysadmins to automate the renewal process. This prevents expired certificates due to forgetting the manual renewal.
    • Certificate lifetime and domain ownership mismatch. You could buy a 2 year certificate for somedomain.com and then sell the domain or just let it expire and have it picked up by someone else. You then have a valid certificate for a domain you no longer ow and you could MitM traffic for the new owner’s website.