4 ms·
Now how the hell do we create a webserver that will work reliably for the next 30 years if we have to embed SSL certificates with built-in expiration dates in t
by xtrapolate 9y ago
Now how the hell do we create a webserver that will work reliably for the next 30 years if we have to embed SSL certificates with built-in expiration dates in the range of 1 to 3 years?
You can use self-signed certificates. Your clients will have to trust them (by updating their stores). That's hardly an ideal solution (deployment and security wise).
More broadly speaking, you can't rely on anything to stay the same in 30 years, in terms of infrastructure. Many companies therefore deliver both the devices themselves, as-well as the systems to control them (ie. custom laptops/tablets). More costly for everyone involved.
- vim_wannabe 9y agoWouldn't self-signed certificates have even more and scarier warnings?
- xtrapolate 9y agoIf your clients trust the self-signed certificates (by updating their certificate stores, adding up a self-signed root CA), then, as of today, as far as I'm aware there won't be any warnings. No guarantees that this situation won't change further down the road.
- dx034 9y agoI doubt there'll be any warnings. Otherwise Chrome wouldn't work in company networks. If you have domains that are just available internally (not even on public DNS), self signing is the logical solution. Still provides you with the advantages of encryption.