Hacker News new | ask | show | jobs
by michaelt 1227 days ago
That's actually kinda normal.

There's no authority above root certificates,* able to sign new certificates - that's what it means to be a root certificate. So root certificates will often have super long durations.

For example, the certificate HN uses is signed by "DigiCert Global Root CA" - valid from 2006 to 2031.

* Unless you count the power of OSes/browsers to push updates with new certificates.