Hacker News new | past | comments | ask | show | jobs | submit login

If you keep your CA secure, no reason that you can't set the expiration of the root cert to something like 10 years.



Will browsers accept that?


Browsers accept a root CA with long lifetime. Certs signed by CAs installed by the user or admin also allow long lifetimes (probably will still for a while).




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: