Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Plenty of the CA root certificates in my browser's trust store have 30 year validity periods. The "keys should have short expiry periods" rule doesn't appear to apply to CAs.

Admittedly, CAs are held to higher standards than most certificate users in terms of keeping keys in hardware security modules and suchlike. So perhaps it's not 100% unjustified that they get longer validity periods.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: