Home Books Training Newsletter Resources
Sign up Log in
book cover

Bulletproof TLS Guide  

A concise, practical guide to deploying SSL/TLS and PKI correctly—choosing protocols and cipher suites, and configuring and testing secure servers with confidence. Written by Ivan Ristić.


< Prev
^ Table of Contents
Next >

1.1.9 Consider Short-Lived Certificates

As of 2026, we have another useful security tool to add to our arsenal—certificates that are valid for such a short period of time that they don’t incorporate any revocation information. These are called short-lived certificates and can last for up to 7 days.

Longer-life certificates come with two problems: (1) they force you to use the backing private keys for a longer period of time and (2) they could be weaponized for a longer period of time if stolen. The latter problem was supposed to be solved using revocation, but that’s never worked properly and is being abandoned, at least for public certificates.

Short-lived certificates have always been a good idea from the security standpoint, but they make more sense now, in a world where issuance automation is widespread. Operationally, however, it remains to be seen if the extreme reduction of certificate lifetime leads to increased outages. More companies need to adopt these types of certificate before we can tell.

< Prev
^ Table of Contents
Next >

Books

  • Apache Security
  • Bulletproof TLS and PKI
  • ModSecurity Handbook
  • OpenSSL Cookbook

Training

  • Practical TLS and PKI

Resources

  • Newsletter
  • SSL/TLS and PKI History
  • Bulletproof TLS Guide

Company

  • Support
  • Website Terms of Use
  • Terms and Conditions
  • Privacy Policy
  • About Us