Conversation

What’s the benefit of “short lived certificates” like Let’s encrypt is starting to offer?
Or in other word why is it better to renew a certificate every six days instead of every three months?

2
0
0
@Erpel whatever this means: " it minimizes exposure time during a key compromise event."

So I guess its better for when a CAs(?) Key gets compromized?
0
0
0
@Erpel technically it shortens the window where someone could exploit a leaked certificate key, as it is constantly rotating. Practically speaking it's bat shit insane because the only way that would happen is if someone is leaking the key, and then you'd have much more pressing problems than certificate security.

Or maybe there's an entirely different reason, i dunno, i mostly checked out of computers and security because all of it is a fucking clown world
0
0
1