3 ms·
There's no problem with that. Assume the key material isn't compromised, since you have to assume that. You imply that Apple is going to keep using the cert un
by mdlowman 11y ago
There's no problem with that. Assume the key material isn't compromised, since you have to assume that.
You imply that Apple is going to keep using the cert until 2035. I can assure you they won't.
- reaperhulk 11y agoIt's also incorrect. The 2035 number is the root certificate. The leaf signer is (as of last night): Not Before: Sep 24 19:09:31 2015 GMT Not After : Oct 23 19:09:31 2017 GMT
- profmonocle 11y ago> Assume the key material isn't compromised, since you have to assume that. The nice thing about root certs is the private key is only needed to sign intermediate certs and CRLs. This means they can be kept offline in a secure location, and only accessed once every few months or so to sign new intermediate certs or CRLs. The actual crypto typically happens in a special locked-down piece of hardware, so that the actual private key never touches the memory or disk of the computer being used. The whole process is called a "key ceremony" and follows strict procedures, with technical staff and outside auditors watching every step. As far as I know, no CA has ever had its root key compromised. It would require physically breaking into a secure facility, or factoring of public key. Considering there's much lower-hanging fruit for anyone attempting to attack PKI, I'm not too concerned with a 20 year root cert lifetime. (Like you say, they could just remove it from future versions of OSX before then!)