• Kairos@lemmy.today
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    1
    ·
    2 days ago

    That completely nullifies the entire point of signature validations.

    • Zak@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      How? Expiration doesn’t grant an unauthorized party access to the private key.

        • Zak@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 days ago

          Which nullifies the point of certificates having an expiration date (limited window for exploiting a compromised certificate, possibility of domains changing hands), not the point of validating the signature (tie responsibility for apps to who owned a domain on a specific date, allow third parties to create blacklists of bad developers).