North American Network Operators Group Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical Re: PKI operators anyone?
Sean Donelan wrote: > > If you re-issue (and check) CRL's daily for 10 year certificates, your > exposure is a day, not 10 years. > Isn't this making the assumption that you know there has been a compromise? With the certificate expiring at a shorter interval you're guaranteed that the exposure is a shorter period of time regardless whether you know the certificate is compromised or not. This however also assumes that the method "they" used to compromise the old certificate cannot be used again to compromise the new one in a similar fashion. Regards, Chris
|