Hacker News new | ask | show | jobs
by ikeboy 4085 days ago
You just made me wonder what happens if you have a cert but let the name expire. Can you MITM your old domain until the cert expires?
1 comments

Sure, if you can get the client to connect through your machine.
If that's the case, shouldn't all certs only be valid until the domain expires, and all domain name sales should require revocation of all certs?
Sure, but how do you enforce the latter?
The latter can't be enforced, but individual buyers can demand that for all known certs.

And I think you can currently get certs expiring later than the domain, which seems wrong to me. Is there a good justification for that?