3 ms·
This is not really an Apple thing, it's an industry trend (and a good one IMO). Apple's generally applying the same criteria Chrome is: https://chromium.googles
by nemo 3y ago
This is not really an Apple thing, it's an industry trend (and a good one IMO). Apple's generally applying the same criteria Chrome is:
https://chromium.googlesource.com/chromium/src/+/HEAD/net/docs/certificate_lifetimes.md#:~:text=Google%20Chrome%20will%20reject%20such,existing%20validity%2Dperiod%20based%20enforcement https://chromium.googlesource.com/chromium/src/+/HEAD/net/do...
- xg15 3y agoSeems Chrome is specifically making an exception for custom root CAs though: > This will only apply to TLS server certificates from CAs that are trusted in a default installation of Google Chrome, commonly known as “publicly trusted CAs”, and will not apply to locally-operated CAs that have been manually configured.
- nemo 3y agoLooking into it further, that's actually Apple's policy as well.