IT admins, get ready to grumble

    • P03 Locke@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      11
      ·
      12 days ago

      This will keep getting shorter until it turns into a calculus problem.

      You won’t even get a certificate, just a token from some SSL token warehouse. Why should I trust it? Because some random company says so!

      • Admiral Patrick@dubvee.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        11 days ago

        Lol, wouldn’t put it past them. Like TLS session keys we have now, but every session key has to be requested from the SSL token warehouse.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      edit-2
      12 days ago

      There are lots of companies and vendors that don’t automate cert renewal. They are all going to be forced into automation with this change.

      The concern is that a compromised device could leak a cert that is then used for attacks.

      • corsicanguppy@lemmy.ca
        link
        fedilink
        English
        arrow-up
        6
        ·
        12 days ago

        The concern is that a compromised device could leak a cert that is then used for attacks.

        Yeah. Everyone gets that.

        The question was whether this is worth the damage seen in the wild thus far.

        And I’m curious too: show me how it’s not some market trying to FUD and FOMO us into yet more rigamarole for the sake of security and also sales. Security is rich in “better safe than sorry” snake oil.

        Are we trading certs lasting ‘too’ long, a problem that may not yet exist, for a much harder problem of properly securing the renewal chain?

        Are we going to have very secure keys but on code with 181 sploits in the supply chain, that we neither know about nor can fix because of rug-pulled compatibility if we did?

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    12 days ago

    Let’s encrypt is about to get even more market share. Suddenly companies will have even less reasons to pay money for a cert.

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    1
    ·
    12 days ago

    God I hate this, dropping it to one year is fine but a month and a half? Fuck that shit.

    Id you can use acme/cert boy it’s fine. But some of us have to manage decades old equipment that doesn’t support it and no we can’t just put a reverse proxy in front we tried.

  • fubarx@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    12 days ago

    We could be heading into daily (or hourly) cert auto-renewals. Clients will have to catch up. But one day, can see it all being hands-free.

  • cmnybo@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    3
    ·
    12 days ago

    What a pain in the ass. I will probably just disable HTTPS and use a VPN or SSH tunnel for my stuff then.