logoalt Hacker News

plqyesterday at 3:03 PM1 replyview on HN

Certificates need expiration dates to be able to garbage collect certificate revocation lists.


Replies

wtallisyesterday at 6:54 PM

Do certificate revocation lists need to keep including certificates that have long since expired? I don't see why root certificates need to expire as long as the certificates signed by those roots all have reasonable expiration windows, unless someone is doing something strange about trusting formerly-valid certificates, or not checking root certificates against revocation lists.