rpki-client
stricter aging policy for Trust Anchor certificates commited to -current
Contributed by Peter N. M. Hansteen on from the trust the anchors not quite as much dept.
Today Job Snijders (job@
) commited code to
rpki-client(8)
to implement a gradual phase in of a stricter policy on TA certificates lifetimes.
The commit message reads,
Subject: CVS: cvs.openbsd.org: src From: Job Snijders <job () cvs ! openbsd ! org> Date: 2024-12-18 16:38:40 CVSROOT: /cvs Module name: src Changes by: job@cvs.openbsd.org 2024/12/18 09:38:40 Modified files: usr.sbin/rpki-client: cert.c Log message: Schedule future rejection of ultra long-lived TA certificates The RPKI ecosystem suffers from a partially unmitigated risk related to long-lived Trust Anchor certificate issuances.