The CA/B Forum voted against reducing the validity period of SSL certificates to 397 days.

On July 26, 2019, Google made a proposal to reduce the maximum lifespan of SSL/TLS server certificates from the current 825 days to 397 days (about 13 months), roughly halving it. Google believes that only full automation of certificate management can eliminate the current security issues often attributed to human error. Therefore, ideally, there should be a move towards the automated issuance of short-lived certificates.

The issue was put to a vote in the CA/Browser Forum (CABF), which sets the requirements for SSL/TLS certificates, including the maximum lifespan.

And on September 10 the results were announced: consortium members voted against on the proposal.

Results

Voting by certificate publishers

In favor (11 votes): Amazon, Buypass, Certigna (DHIMYOTIS), certSIGN, Sectigo (formerly Comodo CA), eMudhra, Kamu SM, Let’s Encrypt, Logius, PKIoverheid, SHECA, SSL.com

Against (20): Camerfirma, Certum (Asseco), CFCA, Chunghwa Telecom, Comsign, D-TRUST, DarkMatter, Entrust Datacard, Firmaprofesional, GDCA, GlobalSign, GoDaddy, Izenpe, Network Solutions, OATI, SECOM, SwissSign, TWCA, TrustCor, SecureTrust (formerly Trustwave)

Abstained (2): HARICA, TurkTrust

Voting by certificate consumers

In favor (7): Apple, Cisco, Google, Microsoft, Mozilla, Opera, 360

Against: 0

Abstained: 0

According to the rules of the CA/Browser Forum, for a positive decision, two-thirds of the certificate issuers and 50% plus one vote among consumers must be in favor.

Representatives of Digicert apologized for missing the vote, where they would have cast their ballot in favor of reducing the lifespan of certificates. They note that for some clients, the reduction in lifespan could pose a problem, but in the long term, it offers security benefits.

Nevertheless, the industry is still not ready to shorten the lifespan of certificates and fully transition to automated solutions. Certification authorities can offer such services, but many clients have yet to implement automation. Therefore, the reduction to 397 days is currently postponed. However, the question remains open.

Now Google might attempt to enforce the standard 'mandatorily', as was done with the protocol Certificate Transparency. Moreover, it is supported by other developers: Apple, Microsoft, Mozilla, and Opera.

It should be noted that full automation is one of the principles upon which the non-profit certificate authority Let’s Encrypt operates. It issues free certificates to anyone who requests them, but the maximum lifespan of a certificate is limited to 90 days. Short certificate lifetimes have two main advantages:

  1. limiting damage from compromised keys and incorrectly issued certificates, as they are used over a shorter time frame;
  2. Short-lived certificates support and encourage automation, which is crucial for the ease of use of HTTPS. If we are going to migrate the entire World Wide Web to HTTPS, we cannot expect the manual updating of certificates by the administrator of every existing site. Once the issuance and renewal of certificates become fully automated, shorter lifetimes for certificates will actually become more convenient and practical.

GlobalSign survey on Habr showed that 73.7% of respondents are "somewhat in favor of" reducing certificate validity periods.

Regarding the hiding of the EV badge for SSL certificates in the address bar, the consortium did not vote on this issue because the browser UI matter is entirely within the purview of developers. New versions of Chrome 77 and Firefox 70, which will remove the special status of EV certificates in the browser address bar, are set to be released in September-October. Here’s how the change looks in the desktop version of Firefox 70:

Previously:

The CA/B Forum voted against reducing the validity period of SSL certificates to 397 days.

It will be:

The CA/B Forum voted against reducing the validity period of SSL certificates to 397 days.

According to security expert Troy Hunt, the removal of EV information from browser address bars essentially buries this type of certificate..

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster