CA/Browser Forum has approved a proposal to reduce the maximum validity of SSL/TLS certificates from the current 398 days to just 47 days by 2029.
The measure, initially proposed by Apple and endorsed by Sectigo, will be implemented in phases over the next four years, marking a significant shift in digital certificate management practices.
The reduction in certificate lifespans will be rolled out gradually:
Three key objectives drive the initiative:
The proposal has received unanimous support from major browser vendors, including Apple, Google, Mozilla Foundation, and Microsoft. Sectigo CEO Kevin Weiss hailed the decision as a “pivotal advancement” for internet security while emphasizing the need for automation in managing frequent renewals.
Tim Callan, Chief Compliance Officer at Sectigo and Vice Chair of the CA/Browser Forum highlighted the operational challenges posed by shorter certificate lifespans but underscored their importance in preparing for quantum-era threats. “Organizations must embrace automated solutions to ensure seamless renewals and avoid service disruptions,” Callan stated.
While the move strengthens security, it introduces operational complexities for enterprises reliant on manual renewal processes. System administrators have expressed concerns over increased workloads, particularly in environments with complex systems or multiple domains.
Businesses must prepare for this transition by updating their infrastructure and adopting automation solutions. The gradual implementation timeline provides a window for adaptation, but enterprises that fail to modernize risk compliance breaches and service outages.
As the industry moves toward shorter certificate lifespans, this change represents not just a technical adjustment but a fundamental shift in how digital trust is managed, ensuring stronger security for an increasingly interconnected world.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…