←back to thread

62 points terminalbraid | 5 comments | | HN request time: 0.771s | source
1. Y-bar ◴[] No.43559138[source]
How will this impact self-signed local certificates? Can we still use a five-year lifespan on those or do we need to reduce it to <398 days?
replies(3): >>43559253 #>>43559268 #>>43560211 #
2. ◴[] No.43559253[source]
3. electroly ◴[] No.43559268[source]
Your local certificates are not bound by the Baseline Requirements at all; they're irrelevant to you. You can do whatever you want if your CA is not in a root program.
4. bawolff ◴[] No.43560211[source]
The article doesn't even mention cert lifetimes.

But the answer is no, self-signed certs dont have to folllw c/ab.

replies(1): >>43561352 #
5. Y-bar ◴[] No.43561352[source]
The links in the article mentions the hard limit on certificate lifetime.