3 ms·
Cert renewal can be automated the same way letsencrypt does it for instance.
by scriptkiddy 9y ago
Cert renewal can be automated the same way letsencrypt does it for instance.
- icebraining 9y agoLet's Encrypt validates during each renewal if the server still controls the DNS and/or HTTP endpoint. The point of the limited duration is to ensure that an attacker who got a copy of the certificate, but who doesn't control the DNS or HTTP endpoint, can't keep using it for long. In this case, I don't see any automated check that can verify that the client trying to renew the cert is the original device, so there's no point in limiting the lifetime of the certificate, unless you send a person to do that verification manually.
- scriptkiddy 9y agoThat is an interesting limitation. I'm sure there is some way to get around it. However, I'm not a network security expert. I just thought using SSL certs for authentication was an interesting idea.