Security and operational considerations when setting intermediate CA cert expiries (cert-manager)

Yes, from the point they get the identity issuer private key…

…at least theoretically. I should probably point out that actually mounting that attack is, uh, complex. :slight_smile: Great reason to automate quickly rotating the identity issuer!

1 Like