6 ms·
Take a look at me.com, for example. Before Apple bought it, it was owned by SnappVille.com. If SSL certificates didn't expire, SnappVille could have continued u
by hwatson 14y ago
Take a look at me.com, for example. Before Apple bought it, it was owned by SnappVille.com. If SSL certificates didn't expire, SnappVille could have continued using their certificates for me.com.
- paxswill 14y agoThat still doesn't fully explain why they expire, as CRLs and OCSP allow certificates to be revoked. I can't quite explain why having an expiration date is safer, I just feel it's a good practice, to protect against possible key compromise.
- tptacek 14y agoSSL certificate revocation is extremely fragile. http://www.imperialviolet.org/2012/02/05/crlsets.html http://www.imperialviolet.org/2012/02/05/crlsets.html
- CJefferson 14y agoBut, they would have to get the private certificate? And if someone got that even while Apple still owned me.com, lots of nasty man in the middle attacks could have been made.