Certificate Expiration Debates

Discussions center on why SSL/TLS certificates expire, the challenges and hassles of renewal and revocation, benefits of short lifetimes for security, and future policies limiting validity periods like 47 days.

➡️ Stable 1.3x Security
4,411
Comments
19
Years Active
5
Top Authors
#5146
Topic ID

Activity Over Time

2008
5
2009
8
2010
10
2011
25
2012
42
2013
76
2014
231
2015
259
2016
294
2017
271
2018
253
2019
378
2020
559
2021
320
2022
243
2023
341
2024
334
2025
723
2026
41

Keywords

MS TrustCor e.g DSA PQ PKI LE HTTPS EvilCorp nagiosplugins.org certificates certificate certs expire cert issued renew compromised trusted browsers

Sample Comments

rav Sep 16, 2017 View on HN

Certificates often change for legitimate reasons, e.g. Let's Encrypt certificates which must be changed every 3 months.

mikek Dec 24, 2015 View on HN

Why do certificates need to expire? It causes a lot of trouble for everyone.

lokar Dec 1, 2022 View on HN

Don’t they tend to cross sign with the old ca cert of a long time due to this?

TedDoesntTalk Aug 31, 2025 View on HN

Is it possible that one day certificate expiration will be a thing of the past?

behringer Apr 14, 2024 View on HN

Someone should tell cloudlare that certificates expire for a reason.

tomjen3 May 13, 2013 View on HN

Wouldn't that break when they need to update the certificate, due to expiration?

em-bee Jun 30, 2025 View on HN

revoking certs does not work. it is so bad that the end result is that by 2029 certificates will not be allowed to be valid longer than 47 days: https://news.ycombinator.com/item?id=43693900

failwhaleshark Jun 10, 2021 View on HN

Won't it basically fix itself in 90 days and 1 second after all the certs are rolled anyhow now that it's on the radar?

windows2020 May 28, 2022 View on HN

It would be nice if certificates didn't arbitrarily expire based on date.

8191 Apr 9, 2023 View on HN

Funny that he considers certificate expiry as vulnerability.