3 ms·
The more pressing reason they expire for web sites is that site ownership can change and you don't want someone else having an infinite lifetime cert for a doma
by allset_ 3y ago
The more pressing reason they expire for web sites is that site ownership can change and you don't want someone else having an infinite lifetime cert for a domain you just bought.
It's also useful to issue short lived certs and use the expiry date to handle revocation rather than maintaining a CRL.