https://www.theregister.com/2024/10/15/ ... _lifespan/
Apple wants TLS certs' maximum validity cut down to 45 days by 2027
Forum rules
The Off-Topic area is a general community discussion and chat area with special rules of engagement.
Enter, read and post at your own risk. You have been warned!
While our staff will try to guide the herd into sensible directions, this board is a mostly unrestricted zone where almost anything can be discussed, including matters not directly related to the project, technology or similar adjacent topics.
We do, however, require that you:
Please do exercise some common sense. How you act here will inevitably influence how you are treated elsewhere.
The Off-Topic area is a general community discussion and chat area with special rules of engagement.
Enter, read and post at your own risk. You have been warned!
While our staff will try to guide the herd into sensible directions, this board is a mostly unrestricted zone where almost anything can be discussed, including matters not directly related to the project, technology or similar adjacent topics.
We do, however, require that you:
- Do not post anything pornographic.
- Do not post hate speech in the traditional sense of the term.
- Do not post content that is illegal (including links to protected software, cracks, etc.)
- Do not post commercial advertisements, SEO links or SPAM posts.
Please do exercise some common sense. How you act here will inevitably influence how you are treated elsewhere.
-
jobbautista9
- Board Warrior

- Posts: 1147
- Joined: 2020-11-03, 06:47
- Location: Philippines
Apple wants TLS certs' maximum validity cut down to 45 days by 2027
And just when I thought Let's Encrypt's validity length for its TLS certificates are insanely too short already... 
https://www.theregister.com/2024/10/15/ ... _lifespan/
https://www.theregister.com/2024/10/15/ ... _lifespan/

Tired of creating stuff!
Avatar artwork by Shinki669: https://www.pixiv.net/artworks/113645617
XUL add-ons developer. You can find a list of add-ons I manage at http://rw.rs/~job/software.html.
-
moonbat
- Knows the dark side

- Posts: 5786
- Joined: 2015-12-09, 15:45
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
Extortion racket if I ever saw one. First push HTTPS everywhere even for public websites that hold no private data or credentials, now keep forking out money to keep your site running.
"One hosts to look them up, one DNS to find them and in the darkness BIND them."

KDE Neon on a Slimbook Excalibur (Ryzen 7 8845HS, 64 GB RAM)
AutoPageColor|PermissionsPlus|PMPlayer|Pure URL|RecordRewind|TextFX
Jabber: moonbat@hot-chili.net

KDE Neon on a Slimbook Excalibur (Ryzen 7 8845HS, 64 GB RAM)
AutoPageColor|PermissionsPlus|PMPlayer|Pure URL|RecordRewind|TextFX
Jabber: moonbat@hot-chili.net
-
Moonchild
- Project founder

- Posts: 38923
- Joined: 2011-08-28, 17:27
- Location: Sweden
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
One year re-issue is already a PITA. 45 days would completely negate any security it would have because of the necessity to fully automate certificate issuance.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
-
suzyne
- Keeps coming back

- Posts: 782
- Joined: 2023-06-28, 22:43
- Location: Australia
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
Whether it's 90 days or half that, isn't everybody using a Let's Encrypt batch file (or similar) that automates the process anyway?
Laptop 1: Windows 11 64-bit, i7 @ 2.80GHz, 16GB, NVIDIA GeForce MX450.
Laptop 2: Windows 10 32-bit, Atom Z3735F @ 1.33GHz, 2GB, Intel HD Graphics.
Laptop 3: Linux Mint 20.3 64-bit, i5 @ 2.5GHz, 8GB, Intel HD Graphics 620.
Laptop 2: Windows 10 32-bit, Atom Z3735F @ 1.33GHz, 2GB, Intel HD Graphics.
Laptop 3: Linux Mint 20.3 64-bit, i5 @ 2.5GHz, 8GB, Intel HD Graphics 620.
-
Basilisk-Dev
- Astronaut

- Posts: 556
- Joined: 2022-03-23, 16:41
- Location: Chamber of Secrets
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
No. Many people still pay for certificates. If that were not the case the certificate authorities would go out of business, or at the very least they would stop selling certificates and transition to other products.
-
Moonchild
- Project founder

- Posts: 38923
- Joined: 2011-08-28, 17:27
- Location: Sweden
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
Nope. check the cert on this site.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
-
athenian200
- Contributing developer

- Posts: 1637
- Joined: 2018-10-28, 19:56
- Location: Georgia
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
Well, that's bad news. I honestly don't know if I'm diligent enough as a person to stay on top of having to update a certificate essentially once a month. That would require staying on top of things in a way I know I would struggle to do consistently, which is part of why I struggle to do things like find employment or anything like that...
I still want to continue Epyrus as a project, but I don't know if I can handle the burden of having an actual website anymore if it gets this involved. Still, they said this would be 2027, and hopefully nothing changes until that time. I'm worried they'll do it in stages, though... cutting it to 6 months unexpectedly, then 3 months, before finally hitting 45 days.
I feel like once a year isn't too bad, 6 months would be annoying but manageable... but if it started getting down to 3 months, it would be starting to hurt, and at 45 days it's at the point where I can't have a personal website anymore because it's too much of a burden.
I still want to continue Epyrus as a project, but I don't know if I can handle the burden of having an actual website anymore if it gets this involved. Still, they said this would be 2027, and hopefully nothing changes until that time. I'm worried they'll do it in stages, though... cutting it to 6 months unexpectedly, then 3 months, before finally hitting 45 days.
I feel like once a year isn't too bad, 6 months would be annoying but manageable... but if it started getting down to 3 months, it would be starting to hurt, and at 45 days it's at the point where I can't have a personal website anymore because it's too much of a burden.
"The Athenians, however, represent the unity of these opposites; in them, mind or spirit has emerged from the Theban subjectivity without losing itself in the Spartan objectivity of ethical life. With the Athenians, the rights of the State and of the individual found as perfect a union as was possible at all at the level of the Greek spirit." -- Hegel's philosophy of Mind
-
Basilisk-Dev
- Astronaut

- Posts: 556
- Joined: 2022-03-23, 16:41
- Location: Chamber of Secrets
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
Off-topic:
Who determines that the certificate authorities themselves are trustworthy? I've always been skeptical of this.
Who determines that the certificate authorities themselves are trustworthy? I've always been skeptical of this.
-
Moonchild
- Project founder

- Posts: 38923
- Joined: 2011-08-28, 17:27
- Location: Sweden
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
Off-topic:
But some alternative peer-trust groups exist as well.
The premise is there that trust is built through peers, similar to the web of trust in pgp/gpg
In general that would be the CA/B forum. Also, cross-signing of root and CA certs also happens where one trusted entity vouches for another to extend trust.Basilisk-Dev wrote: ↑2024-10-17, 13:46Off-topic:
Who determines that the certificate authorities themselves are trustworthy? I've always been skeptical of this.
But some alternative peer-trust groups exist as well.
The premise is there that trust is built through peers, similar to the web of trust in pgp/gpg
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
-
suzyne
- Keeps coming back

- Posts: 782
- Joined: 2023-06-28, 22:43
- Location: Australia
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
45 days would be painful then!
Off-topic:
Looks at new avatar... very scary and fierce!
Looks at new avatar... very scary and fierce!
Laptop 1: Windows 11 64-bit, i7 @ 2.80GHz, 16GB, NVIDIA GeForce MX450.
Laptop 2: Windows 10 32-bit, Atom Z3735F @ 1.33GHz, 2GB, Intel HD Graphics.
Laptop 3: Linux Mint 20.3 64-bit, i5 @ 2.5GHz, 8GB, Intel HD Graphics 620.
Laptop 2: Windows 10 32-bit, Atom Z3735F @ 1.33GHz, 2GB, Intel HD Graphics.
Laptop 3: Linux Mint 20.3 64-bit, i5 @ 2.5GHz, 8GB, Intel HD Graphics 620.
-
Moonchild
- Project founder

- Posts: 38923
- Joined: 2011-08-28, 17:27
- Location: Sweden
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
-
RealityRipple
- Keeps coming back

- Posts: 936
- Joined: 2018-05-17, 02:34
- Location: Los Berros Canyon, California
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
crls? ocsp? don't you love it when one of the biggest tech companies in the world says "the technology has failed us, do it by hand"?
-
Moonchild
- Project founder

- Posts: 38923
- Joined: 2011-08-28, 17:27
- Location: Sweden
Re: Apple wants TLS certs' maximum validity cut down to 45 days by 2027
"do it by hand so we don't need to run the infra any longer for revocation protocols, while still charging ever-increasing amounts for certs".RealityRipple wrote: ↑2024-10-17, 21:40crls? ocsp? don't you love it when one of the biggest tech companies in the world says "the technology has failed us, do it by hand"?
Just another branch of corporate greed, probably.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite