5 ms·
The reason certificates expire is because historically the quality of the generators was known to be poor. NotAfter ensures that a new certificate is created wi
by AtNightWeCode 3y ago
The reason certificates expire is because historically the quality of the generators was known to be poor. NotAfter ensures that a new certificate is created with a better generator every now and then. Today that is not really a problem.
Public CAs are not very secure as NSA proved and I am not sure why there is no better alternative yet.