3 ms·
There might be an official standardized explanation for this but the way I see it, certificate expiry has two reasons: 1) It's an assurance that the verificati
by t0astbread 6y ago
There might be an official standardized explanation for this but the way I see it, certificate expiry has two reasons:
1) It's an assurance that the verification of identities/servers (or whatever) behind the certificate is at least somewhat recent
2) Certificates imply a loose agreement between the certificate holder and the world that the certificate holder keeps the private key safe. The expiry date automatically ends that agreement.
Time is relevant in both cases but it's not that relevant that the timing is exact in web browsing. Identity verification is still about as fresh one day after expiry. The second case is a bit more critical but chances are certificate holders don't leak their private keys immediately after expiry.
Giving a "grace period" with noticeable but non-blocking warnings (something like the "this site recently had an account breach" popup in Firefox perhaps) might cause website operators to find out about the problem without disrupting the service. It would be a good idea to standardize the length of the grace period.
Off the top of my head I can only think of one situation that might turn problematic and that is when an expired certificate gets compromised. I'm not familiar with how CAs do it but I hope renewal automatically revokes the renewed certificate already. It would also need to be possible to explicitly revoke an expired certificate if something like a grace period existed.