• Zak@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    12 hours ago

    Another option is to allow otherwise-valid signatures after expiration. It’s generally still possible to check them.

      • Zak@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        12 hours ago

        How? Expiration doesn’t grant an unauthorized party access to the private key.

          • Zak@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            11 hours ago

            Which nullifies the point of certificates having an expiration date (limited window for exploiting a compromised certificate, possibility of domains changing hands), not the point of validating the signature (tie responsibility for apps to who owned a domain on a specific date, allow third parties to create blacklists of bad developers).