IT admins, get ready to grumble

    • P03 Locke@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      11
      ·
      25 days ago

      This will keep getting shorter until it turns into a calculus problem.

      You won’t even get a certificate, just a token from some SSL token warehouse. Why should I trust it? Because some random company says so!

      • Admiral Patrick@dubvee.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        25 days ago

        Lol, wouldn’t put it past them. Like TLS session keys we have now, but every session key has to be requested from the SSL token warehouse.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      9
      ·
      edit-2
      25 days ago

      There are lots of companies and vendors that don’t automate cert renewal. They are all going to be forced into automation with this change.

      The concern is that a compromised device could leak a cert that is then used for attacks.

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    10
    ·
    25 days ago

    Let’s encrypt is about to get even more market share. Suddenly companies will have even less reasons to pay money for a cert.

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    1
    ·
    25 days ago

    God I hate this, dropping it to one year is fine but a month and a half? Fuck that shit.

    Id you can use acme/cert boy it’s fine. But some of us have to manage decades old equipment that doesn’t support it and no we can’t just put a reverse proxy in front we tried.

  • fubarx@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    25 days ago

    We could be heading into daily (or hourly) cert auto-renewals. Clients will have to catch up. But one day, can see it all being hands-free.

  • cmnybo@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    3
    ·
    25 days ago

    What a pain in the ass. I will probably just disable HTTPS and use a VPN or SSH tunnel for my stuff then.