Impact of Reduced TLS Certificate Lifetimes on CA-Signed SAML Certificates

Cantor, Scott cantor.2 at osu.edu
Thu May 22 19:31:47 UTC 2025


> I find it infuriating when SPs force an update on their certs/keys
> due to expiration, especially because not all of them have an
> automated rollover process.

In their "defense", they don't have a choice. Most SAML software is broken and they need valid certificates in place because they don't get to require their customers not deploy broken software.

Shibboleth is helpless because many of its best features are neutered by all the broken software that don't support them.

Having said that, the legitimate accusation is that that means they should be using long lived certificates, not commercial ones, obviously.

And because they are being ordered to do that by the usual suspects, I don't see what suddenly changes because the lifetime is even shorter. They'd have to admit they had no reason for it to begin with, and if there's one thing ignorant people rarely do, it's admit they were wrong, they just double down.

If nothing else, this will be a fascinating sociological exoeriment.

-- Scott




More information about the users mailing list