Viktor Dukhovni <[email protected]> writes:

>But if the signal is not ignored, and proper automation is applied,
>reliability actually improves.

No, it drops.  You're going from a situation where you've eliminated any
chances of outages due to expired certs to one where you get to play Russian
roulette every single day: Will the cert renewal work, or will it fail for
some reason?  Let's spin the cylinder and see if this is the day our grid goes
down.

Even if you somehow create a 100% successful magical process for replacing
certs that never ever fails, you're now introduced another possible failure
situation, with certs changing constantly there's a chance that something that
relies on them can't handle a new cert, for example because an issuing CA has
renewed as well or something similar.

It's just building in more and more opportunities for failure from a mechanism
that's supposed to be making your infrastructure more robust, not less.

Peter.


_______________________________________________
TLS mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/tls

Reply via email to