this post was submitted on 16 Dec 2024
18 points (100.0% liked)

Security

6186 readers
1 users here now

Confidentiality Integrity Availability

founded 5 years ago
MODERATORS
 

Our longstanding offering won’t fundamentally change next year, but we are going to introduce a new offering that’s a big shift from anything we’ve done before - short-lived certificates. Specifically, certificates with a lifetime of six days. This is a big upgrade for the security of the TLS ecosystem because it minimizes exposure time during a key compromise event.

top 2 comments
sorted by: hot top controversial new old
[–] adespoton@lemmy.ca 3 points 10 months ago* (last edited 10 months ago) (1 children)

So is this specifically for less trusted transition certs, to provide encryption when the old cert is known to be compromised and the new cert isn’t fully deployed yet?

[–] Scipitie@lemmy.dbzer0.com 4 points 10 months ago

Interested amateur disclaimer!

Fast rotating certificates always more secure because the timeframe between beach discovery and system inherent revoke is shorter.

How big the impact in terms of real life is I can't even guess because of the (from my perspective) weird circumstances they must happen to depend on the certificate lifetime itself.

I guess it's just one of these "every but helps" factors more than specific use cases.