About Show #1041
The 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last only 47 days! Todd talks about the first decrease in duration that has already passed - as of March 2026, the longest duration certificate you can buy from certificate authorities is 200 days. At the core of these changes is the problem that certificate revocation just isn't working properly, so a short certificate lifespan is the effective solution. Short certificate lifespans make automation to replace certificates essential - and that's where CertKit and other tools come in!
Links
- Lets Encrypt
- ACME Client Implementations
- CertKit
- Apple's 398 Day Rule
- Microsoft SHA-1 Retirement
- Google Transparency Logs
- Perfect Forward Secrecy
Recorded May 8, 2026