Private-key compromise survives a valid certificate
If somebody steals the private key, the certificate keeps working perfectly for them.
Nothing about the certificate reveals that anybody else has a copy. It remains valid, browsers accept it, and the attacker can impersonate the site or decrypt traffic until it is revoked or expires. Revocation is unreliable in practice, which is why certificate lifetimes keep shortening: the expiry date has become the realistic limit on the damage.
More on TLS and PKI
- TLS encrypts a connection, not endpoint intentionsA sealed pipe to a stranger
- Certificates bind keys to names through trust chainsHeld together by a chain of seals
- Certificate expiry creates operational pressureEvery one of them runs out
- HSTS removes the insecure choice after a browser has learned the policy, while preload can protect the first visit tooThe turning that stops existing
- OCSP stapling moves status evidence closerThe proof comes stapled on
- Mutual TLS authenticates both endsBoth of you show papers
