Impact of Reduced TLS Certificate Lifetimes on CA-Signed SAML Certificates
Tim van Dijen
tvdijen at gmail.com
Sat May 24 16:06:37 UTC 2025
Op 23-5-2025 om 19:43 schreef Peter Schober via users:
> Also, since we're talking certificates, I'd advise you to only ever
> change the private key when (1) the technology/key-size/algorithm or
> (2) the specific key itself is no longer considered sufficiently
> secure, and just change the certificate (i.e., re-wrap the existing
> key into a new certificate with a new expiration date) in all other
> cases.
> That allows those with non-broken software (we're on the Shibboleth
> mailing list here, after all) to skip any key rollover steps (it's not
> actually a key rollover when the key remains the same) and simply
> replace the existing certificate with the new one.
> One can easily determine that the public key (modulus, for RSA) hasn't
> changed and forgo any longwinded rollover ceremonies, then.
>
This assumes self-signed certificates, because no public CA will ever
allow the re-use of a private key. - Tim
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250524/74480bb8/attachment.htm>
More information about the users
mailing list