|
|
|
|
|
by tptacek
335 days ago
|
|
Short certificate lifetimes address the fact that TLS certificate revocation doesn't work. Password rotation --- which is no longer a NIST recommendation! --- addresses the concern that long-term secrets eventually leak. You can intuitively see how different the problem domains are from the fact that certificate lifetimes are far shorter than even the old NIST password rotation rules were, despite the fact that certificates are all stored securely relative to passwords. But whether that's intuitive for you or not, the fact remains: short-lifetime automated certificate provisioning is a response to revocation. |
|
I think short certificate lifetimes will be viewed in the relatively short future as misguided as the old NIST recommendation on passwords.