Hacker News new | ask | show | jobs
by drinchev 4083 days ago
I don't agree. If this happens, same rule should apply for domain name expiration.
2 comments

You just made me wonder what happens if you have a cert but let the name expire. Can you MITM your old domain until the cert expires?
Sure, if you can get the client to connect through your machine.
If that's the case, shouldn't all certs only be valid until the domain expires, and all domain name sales should require revocation of all certs?
Sure, but how do you enforce the latter?
The latter can't be enforced, but individual buyers can demand that for all known certs.

And I think you can currently get certs expiring later than the domain, which seems wrong to me. Is there a good justification for that?

That's actually not a bad idea.