logoalt Hacker News

zeroxfeyesterday at 3:54 PM1 replyview on HN

Expiries are a defence-in-depth that exist primarily for crypt hygiene, for example to protect from compromised keys. If the private key material is well protected, the risk is very low.

However, an org (particularaly a .mil) not renewing its TLS certs screams of extreme incompetence (which is exactly what expiries are meant to protect you from.)


Replies

jp191919yesterday at 4:06 PM

>screams of extreme incompetence

Not unheard of with the military

show 1 reply