The maximum lifespan of TLS certificates will be reduced from 398 to 47 days

Members of the CA/Browser Forum, which serves as a platform for coordinating the collaborative efforts of browser manufacturers and certificate authorities, have voted to reduce the maximum lifespan of TLS certificates. The maximum validity period for TLS certificates will be shortened from 398 days to 47 days unless the CA/Browser Forum revisits this decision in the future. In addition to the validity period of the certificates, it has also been decided to significantly reduce the reuse periods for validation data of objects: for SAN (Subject Alternative Name, where one certificate covers multiple resources, such as being valid for multiple domains), the period will be reduced from 398 days to 10 days, and for non-SAN from 825 days to 398 days.

The change is intended to be implemented gradually: starting March 15, 2026, the maximum validity period for TLS certificates will be reduced to 250 days, then to 100 days from March 15, 2027, and to 47 days starting March 2029. After each stage, processing new certificates that do not meet the aforementioned criteria will result in the display of the error "ERR_CERT_VALIDITY_TOO_LONG" in browsers. Previously, browser manufacturers managed to advocate for the gradual reduction of certificate lifespans from 8 years to 398 days (13 months).

For the new reduction in the lifespan of TLS certificates, 29 members voted in favor, 6 abstained, and no one voted against. Members who voted "for" include: Apple, Google, Microsoft, Mozilla, Amazon, Asseco Data Systems SA (Certum), Buypass AS, Certigna (DHIMYOTIS), Certinomis, DigiCert, Disig, D-TRUST, eMudhra, Fastly, GlobalSign, GoDaddy, HARICA, iTrusChina, Izenpe, NAVER Cloud Trust Services, OISTE Foundation, Sectigo, SHECA, SSL.com, SwissSign, Telia Company, TrustAsia, VikingCloud, Visa. The abstaining members included: Entrust, IdenTrust, Japan Registry Services, SECOM Trust Systems, TWCA.

It is expected that the generation of short-lived certificates will allow for faster implementation of new cryptographic algorithms in the event of vulnerabilities being discovered in current ones, as well as reduce security threats. For example, in the case of a silent certificate leak resulting from a hack, short-lived certificates will prevent attackers from controlling a victim's traffic for an extended period or using the certificates for phishing. More frequent validation and shorter certificate lifespans will also reduce the likelihood that a certificate remains valid after the information it contains becomes outdated and decrease the risk of distributing incorrectly issued certificates.

Moreover, short-lived certificates will drive the adoption of automated certificate management systems, free from human intervention. However, the phasing out of manual certificate renewal practices could lead to negative consequences. It has been noted that some devices that only allow certificate uploads in manual mode may be left with invalid certificates due to the complexity of organizing manual updates every month and a half. This change may also negatively impact the business of certificate authorities that do not provide APIs for automated certificate issuance.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster