3 ms·
I think root certs are long-lifespan, kept in hardware security modules / other cold offline storage, and only used to periodically sign shorter lived intermedi
by jffry 4y ago
I think root certs are long-lifespan, kept in hardware security modules / other cold offline storage, and only used to periodically sign shorter lived intermediates that are the main thing signing leaf certs for sites.
For example, the DigiCert Global Root CA in HN's cert chain is valid from 2006 to 2031.