Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't understand #1 - what prevents you from doing this today? When you generate a certificate you get to pick the expiration date; you are free to make it as short as you want. Don't intermediate certificates exist to implement this strategy?

edit: basically, what stops you from doing this?

Root CA root cert (20y expiration)

v

Root CA intermediate cert (10y expiration)

v

Your intermediate cert (1y expiration)

v

Your short-lived cert (24h expiration)



And who is going to issue you a reasonably-priced intermediate cert? Especially since PKIX name constraints don't actually work, so that intermediate cert would let you sign just about anything.


For your own web servers and your own clients, use your own CA and your own certs.


This isn't a serious solution except for intranets--and this problem exists most pressingly on the internet to begin with.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: