History

Why Maximum Certificate Validity Keeps Getting Shorter

Maximum publicly trusted certificate validity has been repeatedly shortened by industry policy over the years — from as long as five years in the early 2010s, down through three years, two years, and to the current common ceiling of 398 days, set by browser vendor policy (specifically Apple's, which other major browsers effectively followed).

The reasoning behind the trend

Shorter validity limits the exposure window if a certificate is later found to be mis-issued or a key compromised, and forces more frequent revalidation of domain control — reducing the risk of a certificate remaining valid for a domain that's since changed ownership or configuration without anyone noticing.

Where the trend is heading

Discussions of further reductions — down to 90 days or even shorter, matching Let's Encrypt's existing practice — have been actively debated within the CA/Browser Forum, reflecting a broader industry direction toward automation-first certificate management rather than the longer, more manually managed lifecycles common a decade ago.

The specific 2020 industry dispute over the 398-day limit

When Apple, followed shortly by other browser vendors, unilaterally announced the 398-day maximum in 2020, it happened outside the normal CA/Browser Forum ballot process after a formal industry vote on shortening validity had failed to reach consensus — a notable moment where a single browser vendor effectively forced an industry-wide change by simply refusing to trust longer certificates.

What this reveals about how internet security standards actually get enforced

This episode is a useful illustration of a broader pattern in internet governance: browser vendors, by controlling what their software actually trusts, hold outsized practical power to enforce security standards unilaterally, independent of formal standards-body consensus — a dynamic that's shaped several other TLS/certificate policy changes covered throughout this history section.

What the 2020 ballot proposal specifically would have required

The failed 2020 CA/Browser Forum ballot would have formally codified a one-year maximum validity period across the industry through the normal consensus process — its failure to pass, despite browser vendor support, reflected significant pushback from a portion of the CA membership concerned about the operational and customer-relationship impact of shortening validity so significantly through a top-down mandate.

How CAs have adapted their business models to shorter validity periods

As maximum validity periods have shortened, CAs have increasingly emphasized subscription-style, multi-year prepayment options (paying upfront for several years of automatic reissuance under one price) rather than the traditional model of a single long-validity certificate purchase, adapting their commercial offerings to remain viable under the new, shorter technical constraints.

What this trend suggests for certificate management strategy going forward

Given the clear, sustained direction toward shorter validity periods, building certificate management around full automation, rather than manual, calendar-based renewal, is increasingly not just a convenience but close to a necessity, since manually managing renewal for certificates on an ever-shortening cycle becomes proportionally more burdensome each time the maximum validity period is reduced further.

Why this trend is one of the more contested policy shifts covered in this history

Unlike most of the deprecations and hardening measures discussed throughout this section, which achieved fairly broad, uncontroversial industry consensus once the underlying research was clear, the certificate validity shortening trend has repeatedly generated genuine, unresolved disagreement between CAs (concerned about operational and customer burden) and browser vendors (favoring stricter limits), making it one of the more actively contested ongoing policy threads in current certificate governance.

Where the debate likely goes from here

Given the clear historical trajectory toward shorter validity periods and the ongoing tension between CA operational concerns and browser vendor security preferences, further reductions remain a live, actively discussed possibility within CA/Browser Forum circles — worth watching for anyone whose certificate management practices assume today's specific validity limits will remain fixed indefinitely.

The debate over how short certificate validity should get remains one of the more actively contested threads in current CA governance.