{"id":1459,"date":"2021-05-26T18:37:10","date_gmt":"2021-05-26T16:37:10","guid":{"rendered":"https:\/\/macadmin.cz\/?p=1459"},"modified":"2021-05-26T18:37:11","modified_gmt":"2021-05-26T16:37:11","slug":"allowed-lifetime-of-certificates-issued-by-internal-ca","status":"publish","type":"post","link":"https:\/\/macadmin.cz\/?p=1459&lang=en","title":{"rendered":"Allowed lifetime of certificates issued by internal CA"},"content":{"rendered":"\n<p>Last year Apple forced the industry to only accept TLS certificates with validity up to maximum of 398 days. This is documented in <a href=\"https:\/\/support.apple.com\/HT211025\" data-type=\"URL\" data-id=\"https:\/\/support.apple.com\/HT211025\">HT211025<\/a> article. However there is a note explicitly excluding the certificate issued by an internal CA:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>This change will not affect certificates issued from user-added or administrator-added Root CAs.<\/p><\/blockquote>\n\n\n\n<p>Because of this I assumed I could get away with 3 year validity for a certificate issues by our new internal CA. Turns out I was wrong. <\/p>\n\n\n\n<p>Safari 14.1.1 refuses to connect to a site with freshly issued 3-year TLS certificate. So does Chrome 91 but it is more informative about it and presents an error message: <code>NET::ERR_CERT_VALIDITY_TOO_LONG<\/code>.<br><br>Previous change of TLS certificate requirements from 2019 described in article <a href=\"https:\/\/support.apple.com\/HT211025\" data-type=\"URL\" data-id=\"https:\/\/support.apple.com\/HT211025\">HT210176<\/a> article limits the certificate validity to 825 days. There aren&#8217;t any exception listed in this articles. Would Safari and Chrome trust certificate with 2-year validity?<br><br><strong>Yes. Both Safari (14.1.1) and Chrome (91) in macOS 11.4 accept the 2-year certificate signed by internal CA as secure.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last year Apple forced the industry to only accept TLS certificates with validity up to maximum of 398 days. This is documented in HT211025 article. However there is a note explicitly excluding the certificate issued by an internal CA: This change will not affect certificates issued from user-added or administrator-added Root CAs. Because of this &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/macadmin.cz\/?p=1459&#038;lang=en\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Allowed lifetime of certificates issued by internal CA&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1459","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/macadmin.cz\/index.php?rest_route=\/wp\/v2\/posts\/1459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/macadmin.cz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/macadmin.cz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/macadmin.cz\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/macadmin.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1459"}],"version-history":[{"count":3,"href":"https:\/\/macadmin.cz\/index.php?rest_route=\/wp\/v2\/posts\/1459\/revisions"}],"predecessor-version":[{"id":1463,"href":"https:\/\/macadmin.cz\/index.php?rest_route=\/wp\/v2\/posts\/1459\/revisions\/1463"}],"wp:attachment":[{"href":"https:\/\/macadmin.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/macadmin.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/macadmin.cz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}