This is a mystery you don’t want to solve.

  • 0 Posts
  • 2 Comments
Joined 2 years ago
cake
Cake day: March 1st, 2025

help-circle
  • I had no idea “single use certificates” were a thing. It makes sense, although from my personal perspective I have always worked with managed identities and privilege escalation.

    I have almost no internet facing services, although the two I have I might swap for the short lived variants. As you said, risk of misuse due to compromise goes down so that makes sense.

    For my other services, they are all running on HTTPS, but only available internally over LAN or VPN, all with isolated VLANs sort of like a Hub Spoke model. The two certs that are internet facing are basically for getting access to my VPN. Might swap the internal services to short lived anyway if the automation works well, as I said before, it’s fully automated anyway.


  • Thank you for sharing. I had missed the announcement, so pleased to know the option is available.

    I have fully automated the creation and renewal of my certs and have just short of 50 certs that I manage in total. Every single one automated using NixOS / ACME / lego.

    Technically I could easily implement this, just have to switch my config.

    Honest question, are there any particular security benefits to this (especially for a home lab)?

    I can understand the short lived time span further reduces risk of compromise, yet the existing time span is already “much shorter than traditional certificates”. Does it have a substantial impact on our security posture?