5 ms·
It’s funny to me that people talk about this limitation as if it were some kind of virtue.
by dev_dull 7y ago
It’s funny to me that people talk about this limitation as if it were some kind of virtue.
- tty2300 7y agoIts also more secure. Long lived certs risk the possibility that someone who used to own the domain got a certificate on it and it still works after the domain is resold. Once you automate it there is no downside to short lived certs.
- Godel_unicode 7y agoIf only there were a way to revoke certificates. Like, some kind of list.
- yjftsjthsd-h 7y agoIf only such a list were actually effective rather than the majority of clients not bothering to check it.
- lvh 7y agoCRLs do not work in practice, and major clients routinely ignore them.
- dwaite 7y agoRevocation lists get huge, ultimately becoming another reason to limit cert lifetime (you don't have to tell people you revoked a certificate which is expired naturally). Very few things check revocation, unfortunately - it puts an extra hop on the fast path of connecting to a server. OCSP stapling is pretty much the only thing a browser would care about - having the server fetch a signed OCSP response that is good for a limited period of time (say, hours), and send that along with the certificate during negotiation. Or, you could just have the server fetch a certificate thats good for a limited period of time.
- MrStonedOne 7y agoRevocation requires the private key
- pinjiz 7y agoThis is not true. In Let's Encrypt/ACME for example, you can simply obtain authorizations for all the domains a certificate is valid for and request revocation [1]. The only thing you still need to revoke the certificate, is the certificate itself. The certificate can be obtained from CT logs. [1] https://tools.ietf.org/html/rfc8555#section-7.6 https://tools.ietf.org/html/rfc8555#section-7.6
- pinjiz 7y agoOCSP stapling together with OCSP Must Staple is the way to go here. All major browsers support these. Firefox still does normal OCSP requests, Chromes does not. So if you are a Chrome user, to my understanding, there is now way to know if the server certificate was revoked or not, other than OCSP stapling together with OCSP Must Staple. Additionally, both Chrome and Firefox ship a list of revoked certificates, but it may not be updated quickly enough and as far as i can tell it mostly contains roots and intermediates.
- lvh 7y agoShort-term certs _are_ a virtue. Not only do you not have a manual event rare enough for people to forget how to do it, you also don't have to worry about which 15 services someone granted a 10 year wildcard cert to early in the company's history.
- zimpenfish 7y agoHaving once had to regenerate 600+ self-signed certs, test that everything still worked, and then insert them into the 600+ live app servers without breaking anything, all within a two week window because no-one had realised the 10 year expiry was just about to bring everything down, I concur.