Sectigo’s Post

View organization page for Sectigo

52,302 followers

We are endorsing Apple's proposal for shorter SSL/TLS Lifespans. The future of SSL/TLS certificate management is changing. Apple has submitted a ballot to the CA/Browser Forum proposing a reduction of certificate lifespans from 398 days to 47 days by 2028. It's a significant move toward stronger security, better crypto agility, and improved domain control alignment. We fully support this proposal. Shorter certificate lifespans: ✅ Enhance security by minimizing the impact of compromised keys ✅ Promote faster adoption of cryptographic updates ✅ Drive automation, ensuring seamless certificate management ✅ Prepare organizations for the postquantum cryptography era Now is the time to embrace automated certificate lifecycle management to stay ahead. Find out more in our press release: https://lnkd.in/dien4TBf

  • No alternative text description for this image
Edward Hart

PQC student. Venafi API Enthusiast. PKI / X.509 automation. PowerShell, of course

2mo

From the other side of the lens ... bring it on. There's a lotta work to do.

Jim Bracher

Independent Filmmaker at Different Paths Productions

1mo

Is your trust 47 days long?

Like
Reply
Sherman Becraft

Information Security Advisor at Anthem

1mo

2040 per session certificate

Like
Reply
Paul Martin

Founder/Owner of MCMA Technologies

1mo

We will end up with a session length cert

Lukáš Geyer

Data Protection Architect | Cryptography

2mo

...and more money.

I cannot see the point of tapering like that. Ten years was only justified because the bowsers were expected to process CRLs, they didn't of course, but that was on them. The situation is binary, either you do automated renewal or you don't. If you do automated renewal, you might as well wind the validity interval to 7 days.

See more comments

To view or add a comment, sign in

Explore topics