Sigh.
Just got told by a company internal app that it's time to change my password.
Can we please stop with the fake #security? My password is a long string of randomly generated characters. Nobody's going to guess it any time soon.
Signal feed
Post
Remote status
Context
14Sigh.
Just got told by a company internal app that it's time to change my password.
Can we please stop with the fake #security? My password is a long string of randomly generated characters. Nobody's going to guess it any time soon.
As for public CAs requiring TLS certificates to be rotated every 21 seconds, they're doing that because
1. OCSP has epically failed,
2. everybody had to go back to CRLs, and
3. in order for CRLs to not get monstrously huge, certificates must expire quickly so they can be quickly deleted from the CRL.
None of this applies to company internal stuff. Long-lived certificates are still fine in those environments.
Removing the TLS Client EKU is an epic fail and has made a lot of people justifiably upset, but that isn't the same thing as certificate rotation.
I certainly wouldn't mind if someone offered a better alternative to this rapid certificate rotation as it is rather inelegant, but I can't think of one. Can you?
Also, OCSP was even more inelegant. As someone who was dreading having to actually use it in a non-browser client app to validate a server certificate: good riddance.
@argv_minus_one @7666 Both are a problem, you can't have fast expiring certs when the thing that is supposed to make them work barely works.
@argv_minus_one @7666 idk, ask those maintaining the spec and the developers.
Replies
0We can't find the internet
Attempting to reconnect
Something went wrong!
Attempting to reconnect