On Sun, Mar 07, 2021 at 07:31:24PM -0800, Benjamin Kaduk wrote:
> Just to confirm: the scenario you're using to contrast to the one described
> by Viktor (and Nico) is a scenarios in which the certificates expire at
> "never"
> (99991231235959Z)?
>
> I think that at least some people are contrasting against something other
> than that...
Correct, I'm contrasting with N-year certs for N <= 30 (longer if
expected lifetime of device is larger, e.g. switches in the NYC subway
system, though their actual deployed lifetime has well exceeded anything
"planned"). In other words, with certs that will actually need to be
replaced now and then.
Peter's "never" scenario has its place, it's the cases that fall between
"never" and short-lived that I find suboptimal. Do it well, or don't
do it at all.
--
Viktor.
_______________________________________________
TLS mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/tls