Hacker News new | ask | show | jobs
by HendrikR 4087 days ago
This is really awesome. Why do certificates expire in the first place?
1 comments

By having an expiry, revoked certs can be forgotten about once the expiry has passed. We'd need to keep a forever growing list of revocations otherwise.
Also certs get switched to ones with stronger algorithms and longer keylengths after expiry. You also would have to revoke old certs all the time when their crypto isn't safe anymore.