[email protected] writes: >If we assume that the lifetime of the cert is there to limit its window of >vulnerability to factoring, brute force, and other attacks against >computational security properties,
Which only occurs in textbooks. It's probably not necessary to mention that in real life the lifetime of a cert exists to enforce a CA's billing cycle, but beyond that, that it's common practice to re-certify the same key year in, year out, without changing it. So even if you have a cert issued last year, it may contain a key generated a decade ago. >It does, however, seem to ensure a subscription-based revenue model for CAs. That's it exactly. >It would be interesting to see the actual rationale behind these things, if >it were in clear language. I feel a bit like a historical archaeologist >groping for find structure and meaning in something rather complex. See above. Lifetimes were originally introduced to limit exposure but rapidly became a convenient aspect of the CA's billing cycle. In effect validFrom/validTo should be renamed "renewalFeeDueBefore". Peter. _______________________________________________ cryptography mailing list [email protected] http://lists.randombit.net/mailman/listinfo/cryptography
