3 ms·
I assume expiration protects against the case where a valid certificate is forgotten and a bad actor gets their hands on it and abuses it without the domain own
by t0astbread 6y ago
I assume expiration protects against the case where a valid certificate is forgotten and a bad actor gets their hands on it and abuses it without the domain owner noticing. Similar to how some sites enforce session expiration.
- dotancohen 6y agoThat is beginning to appear to be a very corner case. But we didn't know that when the standards were being written.
- t0astbread 6y agoMaybe because certificates are treated as an ephemeral resource that needs to be managed? If a business had "the certificate" for all its lifetime I imagine it would be easier to forget revocation when it's not needed anymore.
- stjohnswarts 6y agoHowever lots of corner cases end up being weak points to be hacked if not properly accounted for