Chrome, Firefox and Safari will limit the lifetime of TLS certificates to 13 months

Chromium developers made a change, which stops trust in TLS certificates that have a lifetime greater than 398 days (13 months). The restriction will only apply to certificates issued on or after September 1, 2020. For long-term certificates received before September 1st, trust will be maintained, but limited 825 days (2.2 years).

An attempt to open a site in a browser with a certificate that does not meet the mentioned criteria will result in the error "ERR_CERT_VALIDITY_TOO_LONG" being displayed. Apple and Mozilla have decided to introduce a similar restriction in Safari ΠΈ Firefox. The change was exhibited for voting by the members of the association CA / Browser Forum, but the solution did not have approved due to disagreements certification centers.

The change may have a negative impact on the business of certification centers that sell cheap certificates with a long validity period of up to 5 years. According to browser manufacturers, the generation of such certificates creates additional security risks, hinders the rapid implementation of new crypto-standards, and allows attackers to control the victim's traffic for a long time or use it for phishing in the event of an imperceptible leak of the certificate as a result of hacking.

Source: opennet.ru

Add a comment