Hacker News new | past | comments | ask | show | jobs | submit login

Curious when it stops. Why not require new certificate every day?



I think you're joking, but at a certain point you're essentially getting live attestation from the CA, with the certificate duration only serving as sort of a caching function to enable faster responses by the server and to avoid overloading the CA. In that model, you might as well have much shorter duration certificates, with maybe the only limiting factor being the capacity of the CA.


I wish I were joking. When I predicted that HTTPS will be mandatory, many thought it was a joke.


CA goes down and everything dies.


When you get to ~30-day duration certificates, everyone's automated, at which point you almost don't care what the duration is anymore.


I do care about CAs becoming SPOF.


The CAs and the browsers do too.


Nice, may I see it? There's clearly some working group or something that produces some reports about mitigating risks of short-lived certificates?


These threads are so weird. There almost certainly is a thread you can go read on a mailing list about this where people discussed this ad nauseam. But nobody is going to go out of their way to prove this to you. We have the before/after picture of the WebPKI with respect to root programs actively managing, and disregarding the concerns of systems administrators and enterprise customers. It's the world of Certificate Transparency, LetsEncrypt and TLS 1.3. The "won't anybody please think of the middlebox operators" perspective, which I'll grant still has some currency in the IETF, is almost completely discredited.


When someone asks "when CA is down or acts sus what do I do?" the response is "stfu you middlebox operator". Of course it's weird lol.


Why not one for each new connection? Then CA could host service to verify re-use.


There are already security professionals that are pushing for 5 minute or less certificates, with mandatory OCSP stapling at even shorter intervals.




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: