Remix.run Logo
elric 3 days ago

This sounds an awful lot like security theatre.

> The information in certificates is becoming steadily less trustworthy over time, a problem that can only be mitigated by frequently revalidating the information.

This is patently nonsensical. There is hardly any information in a certificate that matters in practice, except for the subject, the issuer, and the expiration date.

> Shorter lifetimes mitigate the effects of using potentially revoked certificates.

Sure, and if you're worried about your certificates being stolen and not being correctly revoked, then by all means, use a shorter lifetime.

But forcing shorter lifetimes on everyone won't end up being beneficial, and IMO will create a lot of pointless busywork at greater expense. Many issuers still don't support ACME.