|
|
|
|
|
by likeabatterycar
526 days ago
|
|
> I don't know that cutting 90 days to 45 days would help move the needle further. What does this protect you from? If a private key is stolen from a device? If it went unnoticed for 45 days, the device is probably still compromised, and the threat actor will just steal the new key. If you can automate issuing certificates, you can automate stealing them too. Sounds like a great way to garner more business for Big PKI. |
|
You are not wrong about the malware part though. Said undetected malware would continue to be undetected and continue to expose the private bits no matter how (in)frequently you rotate.