4 ms·
Your guess is correct, the expiration is what adds the security. The main security need this is addressing is terminating access to ex-employees/contractors gi
by scott00 3y ago
Your guess is correct, the expiration is what adds the security.
The main security need this is addressing is terminating access to ex-employees/contractors given a requirement for shared credentials. If the shared credentials are not short term, you have to rotate credentials every time the team changes. If you don't have a system to do it automatically it's pretty easy to forget to do it or do it incompletely. So better just to do it very frequently and automatically so you don't even need to bother with a revocation process.
You might be thinking that you don't have any shared credentials, but effectively any credential that a server has access to is shared, because there's almost certainly at least two people with access to any given server.