Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
fs111
4 months ago
|
parent
|
context
|
favorite
| on:
TLS certificate lifetimes will officially reduce t...
Load on the underlying infrastructure is a concern. The signing keys are all in HSMs and don't scale infinitely.
bob1029
4 months ago
[–]
How does cycling out certificates more frequently
reduce
the load on HSMs?
timmytokyo
4 months ago
|
parent
|
next
[–]
It's all relative. A 47-day cycle increases the load, but a 48-hour cycle would increase it substantially more.
woodruffw
4 months ago
|
parent
|
prev
[–]
Much of the HSM load within a CA is OCSP signing, not subscriber cert issuance.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: