In aggregate this is a very good thing
In aggregate this is a very good thing
It’s easier than ever to run “smaller services”. You don’t even need to pay for a TLS certificate.
The original idea of these certs, that they're very valuable long-lived secrets that have to be carefully hand managed and protected, while simultaneously being accessible to your active infrastructure, was always going to be too brittle. The idea of short-lived secrets that are regularly reissued allows for much more robust validation and less catastrophic failure modes.
I'm generally not dogmatic about this kind of thing and think there are often multiple right answers. But short-lived webpki certs are one of those things where if people don't see the value, I'm convinced they're not thinking about security correctly.
In the past a long-lived EV certificate changing was notable/interesting from a security standpoint. Short-lived certificates just mean anyone who can break into your domain registrar (easy) can create an identical certificate and none of your key storage or security matters.
Precisely because of busywork and process fragility that they invented, with a strictly negative benefit for security and end-users.
Can you propose another path to address this issue?
An attacker who manages to get a cert provider to mint a new certificate for your domain might be able to appear legitimate, but remember that it's a new cert, not an identical one to the cert you already have. You as the domain owner can easily detect this new cert was created using CT logs and visitors to your site can potentially detect two certs for the same domain depending on whether the attacker can convince them to only visit the spoofed site. Short lived certificates also mean the attacker must execute their new cert attack frequently if they want longer term success.
On the other hand, an attacker who manages to penetrate your impenetrable personal cert management security measures now has the real cert they can use to pretend to be you for as long as your certificate is good for. And unless you detected their one-time break-in, there is no way for you or anyone else to tell this is happening since the attacker is using a cert that matches the real one byte for byte.
Edit: I forgot to mention that short-lived certs are also a response to the general challenge with certificate revocation mechanisms as a reliable way to respond to the unlikely event that you actually detected your long-lived cert was stolen. Even if you figured out an attacker stole your certificate, convincing users to not keep treating it as valid has a lot of interesting failure edge cases. You might just have to wait for its validity period to expire.