Published in News

Apple makes systems administrators furious again

by on16 October 2024


Cutting the shelf life of security certificates

The fruity cargo cult Apple has made systems administrators unfortunate enough to work on its software furious with a cunning plan to drastically cut the lifespan of SSL/TLS security certificates from 398 days to just 45 days by 2027.

One admin told Reddit: "This will suck. My least favourite vendor manages ten websites for us, and we have to provide the certs manually every time. Between live and test, this is going to suck."

The proposal, which will likely be voted on by members of the Certification Authority Browser Forum (CA/B Forum) in the coming months, was revealed by Apple during the Forum's autumn meeting. If approved, it will affect all Safari certificates,

While it seems bizarre, it is generally agreed that shorter certificate lifespans enhance internet security by reducing the window for criminals to exploit vulnerabilities.  Google wants to cut down the life of its certificates to 90 days.

However, systems administrators will be heavily responsible for managing these more frequent renewals, and the shortened lifespans will no doubt prove a headache for busy IT security teams juggling many certificates expiring at different times.

The simple answer would be for system administrators to shift their companies off Safari and onto something that does not require updating so often. Apple will, of course, bleat that it is not so secure, but then we are talking about Safari.  

Last modified on 16 October 2024
Rate this item
(3 votes)

Read more about: