Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Considering the potential broad impacts of a revocation action with a Code Signing Certificate issued to the current max validity of 39 months, I’d like to propose we reduce the max validity to 15 months. This would reduce the amount of potentially impacted good code signed by a victim of a takeover attacks and help limit the time an attacker has to abuse a Code Signing Certificate. With that in mind, I’d like to propose the following language to be added to reduce the max validity for Code Signing Certificates to 15 months which includes an effective date for all newly issued Code Signing Certificates.
- Loading branch information
1f40609
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Considering the potential broad impacts of a revocation action with a Code Signing Certificate issued to the current max validity of 39 months, I’d like to propose we reduce the max validity to 460 days (~15 months). This would reduce the amount of potentially impacted good code signed by a victim of a takeover attacks and help limit the time an attacker has to abuse a Code Signing Certificate. With that in mind, I’d like to propose the following language to be added to reduce the max validity for Code Signing Certificates to 460 days which includes an effective date of June 15, 2025, for all newly issued Code Signing Certificates.
1f40609
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The CSBRs currently state, "The validity period for a Code Signing Certificate issued to a Subscriber or Signing Service MUST NOT exceed 39 months." I am not sure if there is a certificate issued to a Signing Service. If no, then may we should delete the term, if yes, then I think that 460 days would also apply.
If no, then another approach would be to say, "The validity period for a Code Signing Certificate issued to a Subscriber MUST NOT exceed 39 months. Effective June 15, 2025, the validity period for newly issued Code Signing Certificates MUST NOT exceed 460-days."