this post was submitted on 17 Apr 2025
197 points (98.0% liked)

Technology

68991 readers
3832 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 2 points 3 days ago

There is plenty of data on compromised certs. I mean if you steal a cert you essentially steal the identity of that server.

I'm just saying before that you had admins connecting from time to time to the server while deploying but after that change it could be years before someone connects. Cert deployment IMO is often one of the last maintenance that is not automated and one of the hardest to automate both safely and reliably.

But for a business that handles it that way it's just straight up an upgrade in security to have shorter certs.