3 ms·
I think it's one of those arguments that disappears once you account for context. No, the datestamp doesn't affect the quality of the encryption. Yes, it migh
by abugheratwork 8y ago
I think it's one of those arguments that disappears once you account for context. No, the datestamp doesn't affect the quality of the encryption. Yes, it might matter if the last time this certificate was vouched for was 100 years ago for one year.
- Kalium 8y agoI mean, I'm one of those crazy people who thinks constantly auto-renewed certs with a one-hour lifetime are a good idea. Though really only achievable when you're working with a private CA, unfortunately. With a sufficiently short lifetime, you can throw up another barrier to compromises.
- kondro 8y agoWhilst I'm sure you're right, I can't think of a single instance where a compromised private key was used to impersonate a website through MiTM. 2+ year expiry on certificates has been pretty commonplace until LetsEncrypt's 90 day policy. It's absolutely possible that this could occur, but practically, the difference between a correctly issued but expired cert and a non-expired one is minor.