3 ms·
I don't know S/MIME, why do you need to keep your old certificates?
by Znafon 5y ago
I don't know S/MIME, why do you need to keep your old certificates?
- gloriousternary 5y agoFrom my understanding S/MIME is pretty much enterprise PGP, so if you don't have your old certificates you can't access old emails that were encrypted using them
- flatiron 5y agoi've always reencrypted when getting a new cert. not sure if thats an antipattern though. i just didn't want to be bothered by which cert encrypted what data
- vbezhenar 5y agoEncryption is performed with private key, not with certificate. If you can issue new certificate for the same private key, it should be able to decrypt old stuff. Rotating keys might be a good security practice, though. But not necessary.