💾 Archived View for bbs.geminispace.org › s › Gemini › 3220 captured on 2023-09-28 at 17:41:45. Gemini links have been rewritten to link to archived content

View Raw

More Information

⬅️ Previous capture (2023-09-08)

➡️ Next capture (2023-11-04)

🚧 View Differences

-=-=-=-=-=-=-

client cert expiration

This may have been mentioned before but when I was setting up my first client certificate (this one) I only gave it a couple years before it expired. I guess it's not a huge deal to add another cert here on bubble and on station but is there anything I might be missing?

I can't think of anything.

I know this dips into user verification but didn't want to open that rabbit hole again.

#client_certificates

Posted in: s/Gemini

🍀 gritty

2023-07-17 · 2 months ago

1 Comment

🚀 skyjake

I think the biggest factor is user convenience. A 100+ year expiration time lets you not worry about it at all, however if your private key leaks, the certificate can then potentially be used any others for a long time. A short expiration time ensures that leaks are less harmful, in case there is no way to revoke the certificates (and on Gemini there isn't one global way to do that), but the price to pay is that you'll need to periodically remember to renew the certificates.

2023-07-18 · 2 months ago