4 ms·
I suspect it's to limit how long a malicious or compromised CA can impact security.
by trothamel 1y ago
I suspect it's to limit how long a malicious or compromised CA can impact security.
- rat9988 1y agoI think op is asking has there been many real case scenarios in practice that pushed for this change?
- hedora 1y agoEquivalently, it also maximizes the number of sites impacted when a CA is compromised. It also lowers the amount of time it’d take for a top-down change to compromise all outstanding certificates. (Which would seen paranoid if this wasn’t 2025.)
- lokar 1y agoMostly this. Today of a big CA is caught breaking the rules, actually enforcing repairs (eg prompt revocation ) is a hard pill to swallow.