Preferences

bayindirh parent
For extremely sensitive systems, I think a more logical endgame is 30 minutes or so. 30 seconds is practically continuous generation.

An semi-distributed (intercity) Kubernetes cluster can reasonably change its certificate chain every week, but it needs an HSM if it's done internally.

Otherwise, for a website, once or twice a year makes sense if you don't store anything snatch-worthy.


nottorp
> once or twice a year makes sense

You don't say. Why are the defaults already 90 days or less then?

bayindirh OP
Because most of the sites on the internet store much more sensitive information when compared to the sites I gave as an example, and can afford 1/2 certificates a year.

90 days makes way more sense for the "average website" which handles members, has a back office exposed to the internet, and whatnot.

nottorp
That's not the average website, that's a corporate website or an online store.

Why do you think all the average web sites have to handle members?

bayindirh OP
Give me examples of websites which doesn’t have any kind of member system in place.

Forums? Nope. Blogging platforms? Nope. News sites? Nope. Wordpresss powered personal page? Nope. Mailing lists with web based management? Nope. They all have members.

What doesn’t have members or users? Static webpages. How much of the web is a completely static web page? Negligible amount.

So most of the sites have much more to protect than meets the eye.

ArinaS
> "Negligible amount."

Neglecting the independent web is exactly what led to it dying out and the Internet becoming corporate algorithm-driven analytics machine. Making it harder to maintain your own, independent website, which does not rely on any 3rd-party to host or update, will just make less people bother.

nottorp
I could move that all your examples except forums do not NEED members or users... except to spy on you and spam you.
panki27
That CRL is going to be HUGE.
Why you think so? Keep in mind that revoked certs are not included in CRLs once expired (because they are not valid any more).

This item has no comments currently.