pwshub.com

Sysadmins slam Apple’s SSL/TLS cert lifespan cuts

Apple wants to shorten SSL/TLS security certificates' lifespans, down from 398 days now to just 45 days by 2027, and sysadmins have some very strong feelings about this "nightmarish" plan. 

As one of the hundreds that took to Reddit to lament the proposal said: "This will suck. My least favorite vendor manages something like 10 websites for us, and we have to provide the certs manually every time. Between live and test this is gonna suck."

The Apple proposal, a draft ballot measure that will likely go up for a vote among Certification Authority Browser Forum (CA/B Forum) members in the upcoming months, was unveiled by the iThings maker during the Forum's fall meeting. 

If approved, it will affect all Safari certificates, which follows a similar push by Google, that plans to reduce the max-validity period on Chrome for these digital trust files down to 90 days.

Max lifespans of certs have been gradually decreasing over the years in an ongoing effort to boost internet security. Prior to 2011, they could last up to about eight years. As of 2020, it's about 13 months.

Apple's proposal would shorten the max certificate lifespan to 200 days after September 2025, then down to 100 days a year later and 45 days after April 2027. The ballot measure also reduces domain control validation (DCV), phasing that down to 10 days after September 2027.

And while it's generally agreed that shorter lifespans improve internet security overall — longer certificate terms mean criminals have more time to exploit vulnerabilities and old website certificates — the burden of managing these expired certs will fall squarely on the shoulders of systems administrators. 

  • Apple drops a bomb on long-life HTTPS certificates: Safari to snub new security certs valid for more than 13 months
  • DigiCert gives unlucky folks 24 hours to replace doomed certificates after code blunder
  • Firefox's Mozilla follows Google in losing trust in Entrust's TLS certificates
  • Entrust faces years of groveling to regain browsers' trust, say rival chiefs

Over the past couple of days, these unsung heroes who keep the internet up and running flocked to Reddit to bemoan their soon-to-be increasing workload. As one noted, while the proposal "may not pass the CABF ballot, but then Google or Apple will just make it policy anyway…"

Even certificate provider Sectigo, which sponsored the Apple proposal, admitted that the shortened lifespans "will no doubt prove a headache for busy IT security teams, juggling with lots of certificates expiring at different times."

The solution, according to Sectigo's Chief Experience Officer Tim Callan, is to automate certificate management — unsurprising considering the firm sells software that does just this. "Automated certificate lifecycle management is going to be the norm for businesses moving forward," Callan told The Register.

However, as another sysadmin pointed out, automation isn't always the answer. "I've got network appliances that require SSL certs and can't be automated," they wrote. "Some of them work with systems that only support public CAs."

Another added: "This is somewhat nightmarish. I have about 20 appliance like services that have no support for automation. Almost everything in my environment is automated to the extent that is practical. SSL renewal is the lone achilles heel that I have to deal with once every 365 days."

Until next year, anyway. ®

Source: theregister.com

Related stories
1 month ago - SaaS seller sets severity to 'critical' Adobe's patch for a remote code execution (RCE) bug in Acrobat doesn't mention that the vulnerability is considered a zero-day nor that a proof-of-concept (PoC) exploit exists, a researcher warns.…
3 days ago - No attacks possible, but enough issues to cause concern Messaging giant WeChat uses a network protocol that the app's developers modified – and by doing so introduced security weaknesses, researchers claim.…
3 weeks ago - More 9.8 bugs? Ai PAPI! Aruba access points running AOS-8 and AOS-10 need to be patched urgently after HPE issued emergency fixes for three critical flaws in its networking subsidiary's networking access points.…
2 weeks ago - Crooks 'like a sysadmin, with a malicious slant' Exclusive An extortionist armed with a new variant of MedusaLocker ransomware has infected more than 100 organizations a month since at least 2022, according to Cisco Talos, which recently...
1 month ago - Sordid search history is evidence in case that could see him spend 35 years for extortion and wire fraud A former infrastructure engineer who allegedly locked IT department colleagues out of their employer's systems, then threatened to...
Other stories
38 minutes ago - Nolah has a wide lineup of great mattresses. CNET's sleep experts put all the Nolah models to the test to find the best fit for you.
1 hour ago - Plus: Australian bank glitch empties accounts; China online slang crackdown; Toshiba teams with Airbus; and more Asia In Brief Baidu CEO Robin Li has proclaimed that hallucinations produced by large language models are no longer a...
1 hour ago - After half a decade of sleeping on a Purple mattress, here are my thoughts on how it's held up and whether you should consider Purple for your next mattress.
2 hours ago - Luckily for Tacoma residents, there are a few great ISP plans to choose from. Here's some more information on speeds and prices to help you decide on the best one for you.
4 hours ago - Best Buy's outlet sale ends today, but you still have a few hours to save on refurbished Ninja appliances before the event ends.