Mandatory short duration TLS certificates are probably coming soon
utcc.utoronto.ca
utcc.utoronto.ca
I'm wondering if it is not a push by big tech lobbyists to push everyone to "cloud managed solutions". Because to be clear this makes life harder and more expensive for on prem solutions and device that might not be often online or freely connected to internet. Also, whatever service you will have in the world, you will be bound to be in frequent contacts with a limited number of actors even if only letsencrypt. And most of these actors, like letsencrypt also might be us based and found by whatever US regulation there would be an anytime.
You can refresh your cert every single day. the cert that gives me https on my home routers web interface doesn’t need that level of scrutiny.
Prior to this proposal by Apple, Google promoted a 90-day maximum lifetime, but they voted in favor of Apple’s proposal almost immediately after the voting period began.
https://news.ycombinator.com/item?id=43693900To be noted that this doesn't just affect certificate generation, but also things like when you have a pool of subcertificates from a given certificate, that will all have to be regenerated and deployed as frequently in cascada, and also, like when you have server or clients or a specific device that validate specific certificates. Their only viable solution would be to accept widely any certificate from one of the big top level "trust" CAs...
Though weirdly, it doesn't even matter to which particular service the host connects or if the domain name actually resolves to anything.
But it does feel like some creeping "platformization" is going on: The requirements make it reliably a pain to run anything that's not connected to the internet, such as LAN-only websites or local web interfaces of IoT devices.
I wonder if the end goal is some sort of "app-storization" of the web, where some entity has the power to ban a site globally, even if registrar, server and users are all in a different country and even if the site only exists internally on some LAN. But then again, I'm unsure if browsers couldn't effectively do that already today - so if they could, why all the effort?
Taking off the conspiracy hat, maybe the tighter update requirements could be a push so that people finally develop some protocol how to securely update certificates on IoT devices. That would at least disprove the conspiracy theory.
Three big problems faced browsers that tried to roll out DANE:
1. DNSSEC adoption on high-traffic/"important" domains is stubbornly very low (this used to be harder to quantify, but there's the Tranco list now; you can just take the top N of it and loop `dig ds` over it to get a %).
2. Middleboxes hassle DNSSEC queries, not everywhere but enough that the browsers need a fallback for browsers on network paths that won't transact DNSSEC, and once you have that fallback you have to account for an adversary who simply downgrades you to the fallback; this is the "you had 10,000 CA certificates, now you have 10,001" problem --- it's also the core of the drama behind the DANE "stapling" fiasco.
3. Browsers were able to get the WebPKI transparency ecosystem deployed using market levers they had over CAs, but they don't have the same leverage over DNS TLD administrators, so there's no "DNS transparency" on the agenda, nor could one plausibly be deployed. Similarly, you can revoke certificates (including CA certs) in ways you can't revoke DNS domains.
It's kind of funny to look at short-duration certificates and ask "why didn't DANE save us from this", because a security engineer might look at this and think "thank God DANE failed an kept us from 30 more years of dangerous, error-prone manual key management".
The APNIC Ping podcast did an excellent 2 part series on the problems of DNSSEC. It puts more responsibility on the DNS systems that are already complex and doing a lot of work.
The CA system with root trusts is just super efficient and easy, so it won.
It’s not perfect, so I’m sure someday it will be replaced, but not by the current options.