TLS certificate lifetimes will "officially" reduce to 47 Days

The CAB Forum or whoever has decided to cut the lifetimes of issued TLS certificates to quite a short duration.

Digicert.com article

I am vaguely familiar with the tradeoffs that they've assessed. Some of it comes down to the programmatic availability of new certificates, which this move will promote, but which is not the principal/stated motivation.

Obviously there is a spillover effect for those who are "commingling" their HTTPS and Gemini services, i.e., using the same certificate and private key for both. It will make the TOFU requirement of Gemini a bit hard on anyone who keeps accessing a commingled Gemini site.

But what mildly irritated me about the article was the notion that the CAB Forum is somehow "official" rather than a private sector monopoly. Surely we can distinguish between things you're forced to do by law and things you're almost forced to do but without any legal backing, and surely this is a worthwhile distinction to maintain?

Gemlog index
Site index