Re: Website Certs Will Soon Last Only 47 Days

Liste des GroupesRevenir à c misc 
Sujet : Re: Website Certs Will Soon Last Only 47 Days
De : invalid (at) *nospam* invalid.invalid (Richard Kettlewell)
Groupes : comp.misc
Date : 12. Apr 2025, 09:28:22
Autres entêtes
Organisation : terraraq NNTP server
Message-ID : <wwv4iytaimx.fsf@LkoBDZeT.terraraq.uk>
References : 1
User-Agent : Gnus/5.13 (Gnus v5.13) Emacs/28.2 (gnu/linux)
Lawrence D'Oliveiro <ldo@nz.invalid> writes:
The CA/Browser Forum (a group that includes those entities that issue
you with attested SSL/TLS certificates) has voted to severely shorten
the valid duration of its certificates from one year to just 47 days
<https://www.computerworld.com/article/3960658/vendors-vote-to-radically-slash-website-certificate-duration.html>.

More concrete details at https://github.com/cabforum/servercert/pull/553.

Some see this as a revenue grab. Yes, it may be, but there are also
good security reasons for doing so.

The “revenue grab” theory is rather dubious. The proposal is from a
device vendor, not a CA; they will make no money from it at all.

If your CA charges by the renewal _and_ doesn’t adjust prices to reflect
the shorter lifetime of individual certificates, then yes, it’ll get a
lot more expensive; an example of shrinkflation. That’d be time to
migrate to a CA with a more reasonable pricing model.

The revenue-grab reason may backfire. For most purposes, a free cert
service like Let’s Encrypt is quite sufficient, and it’s easy enough
to set your system to run a cron task (or systemd timer) to
auto-renew. This already happens by default on a Debian installation,
for example.

Right, the organizations who will have a real problem are those still
renewing certificates manually. They have a choice between spending a
bit more on their own staffing, or automating renewal (probably cutting
their overall costs in the long run).

--
https://www.greenend.org.uk/rjk/

Date Sujet#  Auteur
11 Apr23:32 * Website Certs Will Soon Last Only 47 Days15Lawrence D'Oliveiro
12 Apr04:30 +* Re: Website Certs Will Soon Last Only 47 Days2Oregonian Haruspex
12 Apr04:54 i`- Re: Website Certs Will Soon Last Only 47 Days1Lawrence D'Oliveiro
12 Apr09:28 +* Re: Website Certs Will Soon Last Only 47 Days4Richard Kettlewell
12 Apr11:44 i`* Re: Website Certs Will Soon Last Only 47 Days3Theo
13 Apr01:04 i +- Re: Website Certs Will Soon Last Only 47 Days1Lawrence D'Oliveiro
13 Apr13:03 i `- Re: Website Certs Will Soon Last Only 47 Days1Richard Kettlewell
12 Apr15:06 +* Re: Website Certs Will Soon Last Only 47 Days5John McCue
13 Apr01:05 i`* Re: Website Certs Will Soon Last Only 47 Days4Lawrence D'Oliveiro
13 Apr18:39 i `* Re: Website Certs Will Soon Last Only 47 Days3John McCue
13 Apr19:07 i  +- Re: Website Certs Will Soon Last Only 47 Days1Richard Kettlewell
13 Apr22:33 i  `- Re: Website Certs Will Soon Last Only 47 Days1Lawrence D'Oliveiro
13 Apr16:27 +* Re: Website Certs Will Soon Last Only 47 Days2Richmond
13 Apr22:37 i`- Re: Website Certs Will Soon Last Only 47 Days1Lawrence D'Oliveiro
14 Apr23:28 `- Re: Website Certs Will Soon Last Only 47 Days1Lawrence D'Oliveiro

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal