3 ms·
To clarify, this is the limit for how long they can be to be considered valid. Certificates are encouraged to be of shorter lengths as it reduces their potenti
by SquareWheel 6y ago
To clarify, this is the limit for how long they can be to be considered valid.
Certificates are encouraged to be of shorter lengths as it reduces their potential for abuse. If compromised, a certificate with a long lifespan could be used for years without anyone noticing. A system which doesn't check for revocation is especially vulnerable (though of course, browsers do).
Let's Encrypt certificates are only valid three months, which works well because it's largely automated. It would be good to extend that philosophy elsewhere: automation, and with shorter cycles.
Note the actual limit is 398 days, which gives a small buffer over 1 year.
- joobus 6y ago> it reduces their potential for abuse. It will also increase the number of errors. The more times a thing is done increases the total number of errors occurring doing that thing.
- ceejayoz 6y agoA world-class chef may have nicked their fingers more times than I have with a knife, but I suspect their food is still better than mine.
- SquareWheel 6y agoYou're right that more attempts means more chances at failure, but I don't think it's a 1-to-1 relationship. It's when I don't perform a task for a few years that I tend to make mistakes. Even if it's not an automated process (which I think this encourages), then it's easier to keep your skills sharpened by doing something more often. Would Mozilla have accidentally forgotten to renew their browser certificate recently if it were a more frequent task? It's hard to say, but I think it's likely there'd be a stronger procedure in place. There would need to be.
- reidacdc 6y agoThere's a countervailing effect where the more often you do something, the better you get at it. You're right that the absolute number of errors will certainly rise, but the fraction of attempts which have errors will likely fall. As legacy certs expire, the aggregate quality of certs will likely be higher. A secondary question is whether the gain in security is worth the required effort. Obviously Apple believes this, and LetsEncrypt is pretty easy, so even for hobbyists, it's probably at worst an annoyance.
- slim 6y agowhich makes websites ephemeral and at the mercy of a few authorities. my torrent website could disappear within a few months behind a scary "this site is dangerous" notice
- kspacewalk2 6y agoIt's just gonna be a red strike through the lock in Firefox.
- caymanjim 6y agoIs your torrent website hosting illegal/pirated content? It's probably already dangerous.
- lvh 6y agoWhat does that have to do with certificate lifespan? Authorities go after your domain, not (typically) the CA. Longer certs don't help.
- znpy 6y ago> To clarify, this is the limit for how long they can be to be considered valid. to be fair, there's already a the concept of certificate revocation list and OCSP (on-line certificate status protocol) that helps in order to check the validity of a certificate (that is, whether it has been revoked or not). While short-lived certificates are fine for letsencrypt, pushing the same for the rest of the world looks a bit like an abuse to me.
- wolrah 6y agoThe problem with certificate revocation is that a lot of software treats it as a soft-fail if revocation status can't be verified, rather than a hard fail. That is one of the main reasons for LE's short lifespan. Certificate revocation is not reliable in practice.