You are viewing limited content. For full access, please sign in.

Question

Question

TLS Certificate Lifetimes Reduce to 47 Days

asked on September 15

https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days

 

What is LF doing to prepare for the upcoming changes in 2026 for the new certificate schedules? Is there anything we need to be doing for our on-prem systems?

2 0

Replies

replied one day ago

This isn't a change in what you have to do, the change is how frequently you have to do it. If you haven't automated this process yet, this should push you over the edge. Most certificates used in a Laserfiche solution can be updated with standard tooling. Some of the exceptions are detailed in this post.

2 0
replied one day ago Show version history

And note that the reduced certificate lifetime applies to public certificate authorities (CAs) subject to CA/Browser Forum requirements. In practice, that means only public certs for ports 443 and 8181 (Forms Notification Service) used by web applications are in scope.

tl;dr - Use ACME. Any CA worth their salt supports ACME at this point.

What Is ACME And Why Is It Important? | DigiCert

If you're currently issuing 1-yr certs from an internal CA like Active Directory Certificate Services (AD CS) for backend service TLS bindings (Directory Server port 5049, etc.), those are unaffected by this change. 

Voting Period Begins: SC-081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods

The focus of this ballot is a set of changes to the TLS Baseline Requirements (TBRs). The TBRs address requirements only for certificates which are “intended to be used for authenticating servers accessible through the Internet” [1]. Certificates which match or are compatible with the profiles described in the TBRs can be (and are) used for a variety of purposes not addressed by the TBRs, but these use-cases are not directly in scope of the TBRs nor the changes proposed in this ballot.

That said, certificate lifecycle automation is broadly a good thing, and it's wise to think about how you'd do it anywhere you have certs.

2 0
replied 19 hours ago

Is there a way to automate the selecting of the new certificates for the various Laserfiche utilities, such as the LFDS Configuration Utility, STSEndpoint Utility, etc.?

3 0
You are not allowed to follow up in this post.

Sign in to reply to this post.