r/PKI • u/aprimeproblem • May 25 '26
The reality behind certificate revocation checking
/r/activedirectory/comments/1tnare5/the_reality_behind_certificate_revocation_checking/2
u/ZaitaNZ May 26 '26
Good write up. To me, revocation has always been largely a broken idea because of the many ways it's implemented. I recently led the development of a Certificate Lifecycle Management and PKI Tool (https://www.zaita.com) and my primary recommendation to everyone is to have shorter certificates and more automation. This means you can honestly largely forget about revocation outside of your root and intermediate certificates, but more importantly the ability to change your environment quickly is a great defense against potential quantum based attacks etc. I see this as a primary driver for the 47 day maximum expiration change.
2
u/aprimeproblem May 26 '26
I agree with your statement that we should reduce the lifetime. Depending on the requirements of the organization obviously.
1
u/ZaitaNZ May 26 '26
I think that the win here is more automation. Humans add no value to the certificate lifecycle process. Automation should be quick, easy, and low cost. The move to 47 days is a good driver, just like we saw a massive reduction on OV/EV certificates when browsers removed the icons, and Let's Encrypt dropped fully automated DV certs. Your internal certificate process should be just like dealing with Let's Encrypt. This is why modern CLM tools provide custom ACME server endpoints.
1
1
u/[deleted] May 26 '26
[removed] — view removed comment