Certificate expiry creates operational pressure
Certificates expiring is a security feature and an operational hazard at the same time.
Expiry limits how long a stolen key stays useful. It also means that anything not renewed goes down hard and publicly, and some of the largest outages on record were exactly this. As lifetimes shorten, renewal stops being something a person can remember to do and has to be automated, which is really the point of shortening them.
More on TLS and PKI
- TLS encrypts a connection, not endpoint intentionsA sealed pipe to a stranger
- Certificates bind keys to names through trust chainsHeld together by a chain of seals
- Private-key compromise survives a valid certificateThe certificate is fine
- HSTS removes the insecure choice after a browser has learned the policy, while preload can protect the first visit tooThe turning that stops existing
- OCSP stapling moves status evidence closerThe proof comes stapled on
- Mutual TLS authenticates both endsBoth of you show papers
