Hacker News new | past | comments | ask | show | jobs | submit login

I don't have an explanation for the five years beyond your guess.

Rather sooner, at the end of September 2021 the DST Root CA X3 that cross-signs their existing intermediates expires.

In practice many systems don't directly obey expiries baked into root certs, a self-signed root certificate is largely a vehicle for conveniently moving the key inside it, it's not signed by anybody we trust independently so why care what it does or does not say about that key?

And of course if the IdenTrust / ISRG relationship remains good there's no reason IdenTrust can't sign new Let's Encrypt intermediates with another of their CA roots that hasn't expired. The short lifetime of Let's Encrypt leaf certs means they wouldn't even need to have decided before 2021 what to do about this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: