3 ms·
Why do certificates need to expire? It causes a lot of trouble for everyone.
by mikek 11y ago
Why do certificates need to expire? It causes a lot of trouble for everyone.
- bbrazil 11y agoRevoking certificates is a hard problem (how do you know if the CRL is blocked by an attacker, or just down right now?), so instead we rely somewhat on the certs expiring after a while so that they'll eventually get replaced. It also offers some mitigation against certs being stolen without you realising, as they have a limited lifetime. It's the same theory with passports, credit cards etc.
- mcpherrinm 11y agoAs Admiral Piett said, "It's an older code, sir, but it checks out." Without expiry dates on certificates, we're stuck with trusting whatever we've issued forever. Lists of revoked certificates would grow forever, and work even worse than they do today. At least now, we can stop worrying about ancient certificates after they're expired. Having certs expire and be reissued also ensures there's a continual path to upgrade to newer certificates: I suspect you'd have a much harder time retiring SHA-1 certificates if nobody had any regular-interval incentive to replace their certs.