Impact of Reduced TLS Certificate Lifetimes on CA-Signed SAML Certificates

Steven Premeau steven.premeau at maine.edu
Sat May 24 20:23:31 UTC 2025


On Sat, May 24, 2025 at 12:06 PM Tim van Dijen via users <
users at shibboleth.net> wrote:

> This assumes self-signed certificates, because no public CA will ever
> allow the re-use of a private key.
>

While there is a legitimate debate about the wisdom of reusing private
keys, I have yet to meet a CA that checks for the reuse of a private key
under normal renewal conditions.  (Use and reuse of "known compromised"
keys being the primary exception.)

At least one big public CA has a "renew certificate" button in their
interface that does not require any new information before issuing an
updated certificate.

certbot has the 'reuse-key' option, which is honored by LetsEncrypt....

Steve.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250524/f351f32b/attachment.htm>


More information about the users mailing list