We are endorsing Apple's proposal for shorter SSL/TLS Lifespans. The future of SSL/TLS certificate management is changing. Apple has submitted a ballot to the CA/Browser Forum proposing a reduction of certificate lifespans from 398 days to 47 days by 2028. It's a significant move toward stronger security, better crypto agility, and improved domain control alignment. We fully support this proposal. Shorter certificate lifespans: ✅ Enhance security by minimizing the impact of compromised keys ✅ Promote faster adoption of cryptographic updates ✅ Drive automation, ensuring seamless certificate management ✅ Prepare organizations for the postquantum cryptography era Now is the time to embrace automated certificate lifecycle management to stay ahead. Find out more in our press release: https://lnkd.in/dien4TBf
Is your trust 47 days long?
2040 per session certificate
We will end up with a session length cert
...and more money.
I cannot see the point of tapering like that. Ten years was only justified because the bowsers were expected to process CRLs, they didn't of course, but that was on them. The situation is binary, either you do automated renewal or you don't. If you do automated renewal, you might as well wind the validity interval to 7 days.
PQC student. Venafi API Enthusiast. PKI / X.509 automation. PowerShell, of course
2moFrom the other side of the lens ... bring it on. There's a lotta work to do.