mathstodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for maths people. We have LaTeX rendering in the web interface!

Server stats:

2.8K
active users

#tls

16 posts15 participants3 posts today

happened early April, but worth sharing. Certs will only have 47 days of validity by 2029. validity lengths will progressively get shorter from march 2026 until then. Reusing domain validation material will be limited to 10 days.

IMO this is a very good thing.

this is diff to the very short validity certs that can be issued now. Lets Encrypt will offer 6 day certs by end of yr

github.com/cabforum/servercert

Repository for the CA/Browser Forum Server Certificate Chartered Working Group - Comparing b7fd69b36171d81930e7758482984ce957a1ce7a...abf6c4e3845040069672d58cd2dd80ede8f42012 · cabforum/servercert
GitHubComparing b7fd69b36171d81930e7758482984ce957a1ce7a...abf6c4e3845040069672d58cd2dd80ede8f42012 · cabforum/servercertRepository for the CA/Browser Forum Server Certificate Chartered Working Group - Comparing b7fd69b36171d81930e7758482984ce957a1ce7a...abf6c4e3845040069672d58cd2dd80ede8f42012 · cabforum/servercert

digicert.com/blog/tls-certific

The CA/Browser Forum has officially voted to amend the TLS Baseline Requirements to set a schedule for shortening both the lifetime of TLS certificates.

The maximum certificate lifetime is going down:

- As of March 15, 2026, the maximum lifetime for a TLS certificate will be 200 days.
- As of March 15, 2027, the maximum lifetime for a TLS certificate will be 100 days.
- As of March 15, 2029, the maximum lifetime for a TLS certificate will be 47 days.

www.digicert.comTLS Certificate Lifetimes Will Officially Reduce to 47 DaysThe CA/Browser Forum has officially voted to amend the TLS Baseline Requirements to set a schedule for shortening both the lifetime of TLS certificates.

Nur noch 47 Tage:

#Gültigkeit von #TLS - #Zertifikaten wird drastisch verkürzt

Ab 2029 dürfen #TLS-Zertifikate statt 398 nur noch höchstens 47 Tage lang gültig sein. Der von #Apple eingereichte Vorschlag hat breite Zustimmung erhalten.

Das #CA / #Browser #Forum hat beschlossen, die maximale Gültigkeitsdauer digitaler Zertifikate für den verschlüsselten Datenaustausch via #SSL / #TLS von aktuell 398 auf deutlich geringere 47 Tage zu reduzieren.

golem.de/news/nur-noch-47-tage

Golem.de · Nur noch 47 Tage: Gültigkeit von TLS-Zertifikaten wird drastisch verkürzt - Golem.deBy Marc Stöckel

So it's official: TLS certificate lifetimes will reduce from the current max of 398 days to:
* 200 days in March 2026
* 100 days in March 2027
* 47 days in March 2029

For web servers/proxies etc. it's reasonably simple, at least for smaller orgs but for e.g. network kit it might be more of a challenge. Having a timeframe to aim at definitely focusses the mind!

Via @riskybiz / risky.biz/risky-bulletin-ca-b-

risky.bizRisky Bulletin: CA/B Forum approves 47-days TLS certs - Risky Business MediaThe CA/Browser Forum passed a ballot to reduce the maximum validity of TLS certificates from the current 398 days to just 47 days by 2029. [Read More]
#TLS#PKI#InfoSec
Continued thread

Specific schedule:

March 15, 2026 - Cert validity (and Domain Control Validation) limited to 200 days.
March 15, 2027 - Cert validity (and Domain Control Validation) limited to 100 days.
March 15, 2029 - Cert validity limited to 47 days and Domain Control Validation limited to 10 days.

There's gonna be a lot of complaints about this in change control meetings over the next year200 days.