Chrome also limits the lifespan of TLS certificates to 13 months.

Chrome also limits the lifespan of TLS certificates to 13 months.The developers of the Chromium project made a change, which sets the maximum lifespan of TLS certificates to 398 days (13 months).

This condition applies to all public server certificates issued after September 1, 2020. If a certificate does not comply with this rule, the browser will reject it as invalid, specifically responding with the error ERR_CERT_VALIDITY_TOO_LONG.

For certificates issued before September 1, 2020, trust will be maintained and limited to 825 days (2.2 years), as it is today.

Previously, the limitation on the maximum lifespan of certificates was implemented by Firefox and Safari browser developers. This change also takes effect on September 1.

This means that websites using SSL/TLS certificates with long lifetimes issued after the cutoff point will generate privacy errors in browsers.

Chrome also limits the lifespan of TLS certificates to 13 months.

Apple was the first to announce the new policy at the CA/Browser forum meeting in February 2020.By implementing the new rule, Apple promised to apply it across all iOS and macOS devices. This will pressure website administrators and developers to ensure their certificates meet the requirements.

The shortening of certificate lifespans has been discussed for several months by Apple, Google, and other CA/Browser participants. This policy has its advantages and disadvantages.

The goal of this step is to enhance website security by ensuring that developers use certificates with the latest cryptographic standards, and to reduce the number of old, forgotten certificates that could potentially be stolen and reused for phishing and drive-by malware attacks. If attackers can break the cryptography of the SSL/TLS standard, shorter-lived certificates will facilitate a transition to more secure certificates in about a year.

Shortening certificate lifespans has some drawbacks. It has been noted that by increasing the frequency of certificate replacements, Apple and others are also slightly complicating the lives of website owners and companies that must manage certificates and compliance.

On the other hand, Let’s Encrypt and other certification authorities encourage webmasters to implement automated procedures for updating certificates. This reduces human overhead and the risk of errors as the frequency of certificate renewals increases.

As is known, Let’s Encrypt issues free HTTPS certificates that expire after 90 days and provides tools for automation of renewal. So now these certificates fit even better into the overall infrastructure as browsers impose a limit on the maximum validity period.

This change was put to a vote by members of the CA/Browser Forum association, but the decision was not approved due to disagreement among the certification authorities..

Results

Voting by certificate publishers

In favor (11 votes): Amazon, Buypass, Certigna (DHIMYOTIS), certSIGN, Sectigo (formerly Comodo CA), eMudhra, Kamu SM, Let’s Encrypt, Logius, PKIoverheid, SHECA, SSL.com

Against (20): Camerfirma, Certum (Asseco), CFCA, Chunghwa Telecom, Comsign, D-TRUST, DarkMatter, Entrust Datacard, Firmaprofesional, GDCA, GlobalSign, GoDaddy, Izenpe, Network Solutions, OATI, SECOM, SwissSign, TWCA, TrustCor, SecureTrust (formerly Trustwave)

Abstained (2): HARICA, TurkTrust

Voting by certificate consumers

In favor (7): Apple, Cisco, Google, Microsoft, Mozilla, Opera, 360

Against: 0

Abstained: 0

Now browsers are enforcing this policy without the consent of the certification authorities.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster