news.volyx.in

TLS certificate lifetimes will officially reduce to 47 days (digicert.com)

512 points by crtasm · 473 days ago · 676 comments on HN

Article summary

The CA/Browser Forum has voted to reduce the maximum lifetime of TLS certificates to 47 days, with the goal of improving security by minimizing risks from outdated certificate data and encouraging automation. The change will be implemented in stages, with the maximum lifetime decreasing to 200 days in 2026, 100 days in 2027, and finally 47 days in 2029. This change is expected to make automation essential for effective certificate lifecycle management. The new rule also reduces the maximum period for reusing domain validation information.

Main themes

  • TLS certificate lifetimes
  • Certificate automation
  • Security risks
  • CA/Browser Forum
  • Certificate management

What commenters say

  • The reduction of TLS certificate lifetimes to 47 days will cause significant problems for smaller organizations and enterprises that are not prepared for automation.
  • The change will improve security by reducing the risk of outdated certificate data and encouraging automation, making it harder for attackers to exploit compromised certificates.
  • The new rule will lead to increased costs and complexity for organizations that are not already using automated certificate management solutions.
  • The benefits of shorter certificate lifetimes, such as improved security, outweigh the potential drawbacks, such as increased complexity and costs.
  • The CA/Browser Forum's decision is motivated by a desire to reduce legal exposure rather than improve security.
  • The change will have a disproportionate impact on smaller sites and organizations that rely on off-the-shelf software and may not have the resources to implement automated certificate management.
  • The use of automation tools, such as ACME clients, can simplify the process of certificate renewal and reduce the risk of errors or downtime.
  • The reduction of certificate lifetimes may not address the root causes of security risks, such as certificate theft or compromised CAs, and may even create new problems, such as increased certificate issuance costs.