Ansicht umschalten
Avatar von Kiria
  • Kiria

mehr als 1000 Beiträge seit 01.04.2011

Re: Wird Zeit....

Nein. Das ist beabsichtigt und ein Sicherheitsfeature.

The Technical Advisory Board34, chose a 90-day certificate lifetime to start with, with an expectation that people will want to auto-renew at the 60-day mark.

When an attacker compromises a certificate's private key, they may bypass revocation checks45 and use that certificate until it expires. Shorter lifetimes decrease the compromise window in situations like Heartbleed21.

Offering free certificates with a shorter lifetime provides encouragement for operators to automate issuance. Automated issuance decreases accidental expiration, which in turn may reduce warning-blindness in end-users.

Let's Encrypt's total capacity is bound by its OCSP signing capacity, and LE is required to sign OCSP
responses for each certificate until it expires. Shorter expiry period means less overhead for certificates that were issued and then discarded, which in turn means higher total issuance capacity.

Bewerten
- +
Ansicht umschalten