Remix.run Logo
saltcured 2 days ago

I understand the optimization curve you are talking about. But, my coffee and I think my answer is more accurate as the theoretical asymptote as you reduce certificate lifetimes... you can never really have a zero lifetime certificate in a TLS connection, but you can reduce it to the handshake sequence necessary to establish the connection and its authenticated symmetric cipher.

woodruffw 2 days ago | parent [-]

Yes. But the point is that isn’t going to happen. It would directly undermine the goal of eliminating the stability and scaling issues with OCSP.