Hacker News new | ask | show | jobs
by wangweij 3753 days ago
Expired and compromised are two different things. If compromised, it will be published in a CRL with a reason flag.
1 comments

The reason why certificates expire is because they will become easy to crack as computers get faster. So this would effectively be removing the expiry date. Now you can crack any old certificate and sign things claiming that you did it before the certificate expired.
As someone above has already said.

To do this, you'd need to compromise or convince a trusted timestamping authority to sign your signing request with an old date.