28 November 2020
Apple introduces a 1-year SSL limit for Safari
Starting September 1, Apple's Safari browser will no longer trust SSL / TLS certificates that are valid for more than 398 days. This is the equivalent of a one-year certificate plus a grace period of renewal.
Apple announced its decision at a meeting on February 19 at the CA / Browser (CA / B Forum), which consists mainly of certification bodies and several major browsers.
Although there was no official statement anywhere, this was reported by those present at the meeting. The good news is that this change doesn't really come as a surprise, and the SSL industry is ready for it - so there won't be any major impacts on customers or service providers.
What site administrators need to know
In fact, any SSL / TLS certificates issued before September 1, 2020 are not affected by this change. They will remain valid (prohibiting any unrelated revocation of certificates) for the entire two-year period and will not need to be changed or replaced. However, any certificates issued on or after September 1 will need to be renewed annually to keep Safari trusted.
This means that existing certificate management practices will need to be streamlined and improved. This encourages large organizations to find a reliable certificate management solution so that they no longer rely on manual management.
What resellers need to know
You can continue to issue two-year certificates until August 31, 2020, which your customers can use until they expire. However, any certificates you issue after this date must be issued for one year to remain valid for Safari.
This means that any two-year certificates you sell will need to be reissued in a year so that they can continue to be trusted by the browser.
New option: SSL long-term subscription
Fortunately, leading market players have decided to create new certificate lifecycle automation options and subscription plans that will make it easier to manage certificates for shorter certificate life cycles.
Some organizations have announced a new option to purchase / implement SSL. Sectigo has already developed its SSL subscription plan, and DigiCert will roll out its multi-year plans by September. With these long-term subscriptions based on SSL services, webmasters will be able to purchase coverage for longer periods and issue a certificate as many times as needed, with the maximum validity.
This option has several advantages:
- Cost: this allows customers to continue to receive a long-term discount, which saves money
- Customers will purchase a subscription only once and will not have to worry about it again for five years
This way, customers can purchase SSL coverage for an extended period of time (for example, 5 years) and then simply renew the certificate each year to renew it - saving money and time. It sounds like a win for everyone.
What's next
Once someone starts taking these steps, everyone else is likely to change their certificates from two years to a year. We hope that this transition will have the planned effect - increased website security and improved certificate management.
0
0
Comments
Facebook improves connectivity in the African region with an undersea internet cable
7 November 2021Can blind spots be avoided when monitoring DCs?
3 November 2021Influence of automation in DC on engineering personnel
30 October 2021The frequency of accidents in DC has decreased and the sum of damage has increased significantly
26 October 2021
How to avoid mistakes when choosing a hosting
How to avoid mistakes when choosing a hosting
Chinese manufacturer Loongson will enter the market ..
Chinese manufacturer Loongson will enter the market with 16-core processor in 2020
Please sign-in to comment here